Vulnerability Description
Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Demarc Security | Puresecure | 1.0.5_for_unix |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0168.htmlExploitPatchVendor Advisory
- http://online.securityfocus.com/archive/1/267941Patch
- http://www.iss.net/security_center/static/8854.phpPatchVendor Advisory
- http://www.osvdb.org/5239
- http://www.securityfocus.com/bid/4520ExploitPatchVendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-04/0168.htmlExploitPatchVendor Advisory
- http://online.securityfocus.com/archive/1/267941Patch
- http://www.iss.net/security_center/static/8854.phpPatchVendor Advisory
- http://www.osvdb.org/5239
- http://www.securityfocus.com/bid/4520ExploitPatchVendor Advisory
FAQ
What is CVE-2002-0539?
CVE-2002-0539 is a vulnerability with a CVSS score of 10.0 (HIGH). Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session ID that is stored in the s_key cookie.
How severe is CVE-2002-0539?
CVE-2002-0539 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-0539?
Check the references section above for vendor advisories and patch information. Affected products include: Demarc Security Puresecure.