Vulnerability Description
A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arialsoftware | Campaign Enterprise | <= 11.0.551 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0103.htmlBroken Link
- http://sadgeeksinsnow.blogspot.dk/2012/10/my-first-experiences-bug-hunting-part-ExploitThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79508Third Party AdvisoryVDB Entry
- https://www.securityfocus.com/archive/1/524462ExploitThird Party AdvisoryVDB Entry
- https://www.securityfocus.com/bid/56117/infoThird Party AdvisoryVDB Entry
- http://archives.neohapsis.com/archives/bugtraq/2012-10/0103.htmlBroken Link
- http://sadgeeksinsnow.blogspot.dk/2012/10/my-first-experiences-bug-hunting-part-ExploitThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/79508Third Party AdvisoryVDB Entry
- https://www.securityfocus.com/archive/1/524462ExploitThird Party AdvisoryVDB Entry
- https://www.securityfocus.com/bid/56117/infoThird Party AdvisoryVDB Entry
FAQ
What is CVE-2012-3821?
CVE-2012-3821 is a vulnerability with a CVSS score of 4.3 (MEDIUM). A Security Bypass vulnerability exists in the activate.asp page in Arial Software Campaign Enterprise 11.0.551, which could let a remote malicious user modify the SerialNumber field.
How severe is CVE-2012-3821?
CVE-2012-3821 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-3821?
Check the references section above for vendor advisories and patch information. Affected products include: Arialsoftware Campaign Enterprise.