Allaire Spectra 1.0 Webtop Vulnerability...

- AV AC AU C I A
发布: 2000-01-04
修订: 2025-04-13

Allaire Spectra is a web-based e-commerce product. The Webtop portion of Spectra allows for the creation of customizable web interfaces for administration of the various services provided by the Spectra system. These interfaces can be tailored to provide seperate functionality for users with different roles in the administration and deployment of the product. Due to an error in a configuration file shipped with Spectra, users who have access to only one part of the Webtop feature can gain access to all other Webtop enabled controls by typing in the explicit URL of those features. Note that to exploit this vulnerability the attacker must already have authorized access to at least one part of the Webtop interface.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息