The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting to the application on port 32123, as demonstrated by setting the action option to wizardStep1.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2010-03-03T20:00:00
Updated: 2024-08-07T07:08:38.267Z
Reserved: 2010-03-03T00:00:00
Link: CVE-2009-4657

No data.

Status : Deferred
Published: 2010-03-03T20:30:00.400
Modified: 2025-04-11T00:51:21.963
Link: CVE-2009-4657

No data.