Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:LAYTON-HELPBOX-AUTH-BYPASS

Severity

Medium

Recommended

No

Category

HTTP

Keywords

Layton Technologies Helpbox editrequestuser.asp Possible Authorization Bypass

Release Date

2013/01/18

Update Number

2226

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Layton Technologies Helpbox editrequestuser.asp Possible Authorization Bypass


This signature detects attempts to access a vulnerable Layton Helpbox script. Due to a critical bug in the application, such attempts could allow an attacker to bypass mandatory authorization checks and gain access to sensitive user data.

Extended Description

editrequestuser.asp in Layton Helpbox 4.4.0 allows remote authenticated users to change arbitrary support-ticket data via a modified sys_request_id parameter.

Affected Products

  • layton_technology helpbox 4.4.0

References

  • BugTraq: 56298
  • CVE: CVE-2012-4975

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out