CVE
- Id
- 76876
- CVE No.
- CVE-2014-9575
- Status
- Candidate
- Description
- VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin settings, via an encoded : (colon) character in the Authorization HTTP header.
- Phase
- Assigned (20150108)
- Votes
- None (candidate not yet proposed)
- Comments