CVE-2014-3006

Sitepark Information Enterprise Server (IES) 2.9 before 2.9.6, when upgraded from an earlier version, does not properly restrict access, which allows remote attackers to change the manager account password and obtain sensitive information via a request to install/.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sitepark:information_enterprise_server:2.9:*:*:*:*:*:*:*

History

21 Nov 2024, 02:07

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2014/Apr/317 - () http://seclists.org/fulldisclosure/2014/Apr/317 -
References () http://www.securityfocus.com/archive/1/531986/100/0/threaded - () http://www.securityfocus.com/archive/1/531986/100/0/threaded -
References () http://www.securityfocus.com/bid/67165 - () http://www.securityfocus.com/bid/67165 -
References () https://www.lsexperts.de/advisories/lse-2014-04-10.txt - () https://www.lsexperts.de/advisories/lse-2014-04-10.txt -

Information

Published : 2014-05-02 14:55

Updated : 2024-11-21 02:07


NVD link : CVE-2014-3006

Mitre link : CVE-2014-3006

CVE.ORG link : CVE-2014-3006


JSON object : View

Products Affected

sitepark

  • information_enterprise_server
CWE
CWE-264

Permissions, Privileges, and Access Controls