CVE-2009-4367
Last modified
CVE-2009-4367 is a vulnerability of currently unknown severity. The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear the server cache via crafted SOAP requests with arbitrary Username and Password values, possibly related to a direct request.. EPSS estimates a 6.09% chance of exploitation in the next 30 days.
Description
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers to bypass authentication and (1) upload files, (2) download files, (3) list directories, and (4) clear the server cache via crafted SOAP requests with arbitrary Username and Password values, possibly related to a direct request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Sitecore | Staging Module | <= 5.4.0 | 080625 |
References
- http://secunia.com/advisories/37763Vendor Advisory
- http://secunia.com/advisories/37763Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4367?
How severe is CVE-2009-4367?
How do I fix CVE-2009-4367?
Are you affected by CVE-2009-4367?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
