CVE Database
/

CVE-2010-4506

Back to search

CVE-2010-4506

Published: Feb 7, 2011

Modified: Aug 7, 2024

PUBLISHED

Description

Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.

VendorProductVersions

n/a

n/a

affected
n/a

References

sspr-ssl-security-bypass(65439)
vdb-entry
x_refsource_XF
46452
vdb-entry
x_refsource_BID
8065
third-party-advisory
x_refsource_SREASON

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now