Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Garrett Held

Researcher fromTrustwave's SpiderLabs
#45213of 56,335
6.2Total CVSS
Vulnerabilities · 1
PT-2011-1586
6.2
2011-02-07
Microsoft · Internet Explorer · CVE-2010-4506
**Name of the Vulnerable Software and Affected Versions** Passlogix v-GO Self-Service Password Reset (SSPR) and OEM versions prior to 7.0A **Description** The issue allows physically proximate attackers to execute arbitrary programs without authentication. This can be achieved by triggering the use of an invalid SSL certificate and utilizing the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog, which is reachable from the "Certificate Export" wizard. **Recommendations** For versions prior to 7.0A, update to version 7.0A or later to resolve the issue.