Vulnerabilities > CVE-2007-3986 - Unspecified vulnerability in Securecomputing Securityreporter 4.6.3

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) 4.6.3 allows remote attackers to bypass authentication via a name parameter that specifies the eventcache directory and a non-GIF file, which causes the $dontvalidate variable to be set to true. NOTE: a separate traversal vulnerability could be leveraged to download arbitrary files.

Vulnerable Configurations

Part Description Count
Application
Securecomputing
1

Nessus

NASL familyCGI abuses
NASL idSECURITYREPORTER_463P1.NASL
descriptionThe
last seen2020-06-01
modified2020-06-02
plugin id25994
published2007-09-06
reporterThis script is Copyright (C) 2007-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/25994
titleSecurityReporter < 4.6.3p1 Multiple Vulnerabilities