The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor prior to 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sourcefire 3d sensor 4.8 |
||
sourcefire 3d sensor 4.8.0.4 |
||
sourcefire defense center 4.8 |
||
sourcefire defense center 4.8.0.3 |
||
sourcefire defense center |
||
sourcefire 3d sensor 4.8.0.3 |
||
sourcefire defense center 4.8.0.4 |
||
sourcefire 3d sensor |