Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin settings, via an encoded : (colon) character in the Authorization HTTP header.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
VDG Security SENSE 权限许可和访问控制漏洞
Vulnerability Description
VDG Security SENSE(前称DIVA)是荷兰VDG Security公司的一套视频管理系统(VMS)。该系统提供了一个友好的用户界面用于控制所有的实时图像和存储的视频数据。 VDG Security SENSE 2.3.14及之前版本中存在安全漏洞。远程攻击者可借助Authorization HTTP头中的‘encoded:’参数利用该漏洞绕过身份验证,读取和修改任意插件设置。
CVSS Information
N/A
Vulnerability Type
N/A