HIGH
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 does not require authentication for (1) the "LOG." command, which allows remote attackers to create or overwrite arbitrary files; (2) the SETTINGSFILE command, which allows remote attackers to overwrite the ini file, and reconfigure VSAOD or cause a denial of service; or (3) the UNINSTALL command, which allows remote attackers to cause a denial of service (daemon shutdown)
Published Aug 3, 2007
10.0
HIGHCVSS 2.0
EPSS 4.83%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.