perfact::mpa Insecure Direct Object Reference
Posted by deepcore on March 2, 2016 – 8:02 pm
The SySS GmbH found out that any logged in user is able to download valid VPN configuration files of arbitrary existing remote sessions. All an intruder needs to know is the URL with the dynamic parameter “brsessid”. Due to the modification of this incremental increasing integer value, it is possible to enumerate and download a valid VPN configuration file for every existing remote session.
Post a reply
You must be logged in to post a comment.