mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 23:27:33 +02:00
814 B
814 B
CVE-2014-5375
Description
The server in Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 does not properly validate the message owner matches the submitting user, which allows remote authenticated users to impersonate arbitrary users via the UserId and Owner tags.
POC
Reference
- http://packetstormsecurity.com/files/128484/Moab-User-Impersonation.html
- http://packetstormsecurity.com/files/128484/Moab-User-Impersonation.html
Github
No PoCs found on GitHub currently.