Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.103460
Category:Web application abuses
Title:Sourcefire Defense Center < 4.10.2.3 Multiple Vulnerabilities - Active Check
Summary:Sourcefire Defense Center is prone to multiple vulnerabilities,; including multiple arbitrary file download vulnerabilities, an arbitrary file deletion; vulnerability, a security bypass vulnerability, and an HTML injection vulnerability.
Description:Summary:
Sourcefire Defense Center is prone to multiple vulnerabilities,
including multiple arbitrary file download vulnerabilities, an arbitrary file deletion
vulnerability, a security bypass vulnerability, and an HTML injection vulnerability.

Vulnerability Impact:
Exploiting these vulnerabilities may allow an attacker to view
or delete arbitrary files within the context of the application, gain unauthorized access and
execute HTML and script code in the context of the affected site, steal cookie-based
authentication credentials, or control how the site is rendered to the user. Information
harvested may aid in launching further attacks.

Affected Software/OS:
Sourcefire Defense Center prior to version 4.10.2.3.

Solution:
Update to version 4.10.2.3 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

CopyrightCopyright (C) 2012 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.