The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components.
Name | Vendor | Start Version | End Version |
---|---|---|---|
3d_sensor | Sourcefire | * | 4.8.1 (including) |
3d_sensor | Sourcefire | 4.8 (including) | 4.8 (including) |
3d_sensor | Sourcefire | 4.8.0.3 (including) | 4.8.0.3 (including) |
3d_sensor | Sourcefire | 4.8.0.4 (including) | 4.8.0.4 (including) |
Defense_center | Sourcefire | * | 4.8.1 (including) |
Defense_center | Sourcefire | 4.8 (including) | 4.8 (including) |
Defense_center | Sourcefire | 4.8.0.3 (including) | 4.8.0.3 (including) |
Defense_center | Sourcefire | 4.8.0.4 (including) | 4.8.0.4 (including) |