CVE-2010-4506
Last modified
CVE-2010-4506 is a vulnerability of currently unknown severity. Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Passlogix V-Go Self-Service Password Reset And Oem | 7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4506?
How severe is CVE-2010-4506?
How do I fix CVE-2010-4506?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-4500Multiple SQL injection vulnerabilities in contact.php in MRC…
- CVE-2010-4501Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2010-4502Integer overflow in KmxSbx.sys 6.2.0.22 in CA Internet Secur…
- CVE-2010-4503SQL injection vulnerability in indexlight.php in Aigaion 1.3…
- CVE-2010-4504Multiple cross-site scripting (XSS) vulnerabilities in eSynd…
- CVE-2010-4505Multiple SQL injection vulnerabilities in login.php in Injad…
- CVE-2010-4507Multiple cross-site request forgery (CSRF) vulnerabilities o…
- CVE-2010-4508The WebSockets implementation in Mozilla Firefox 4 through 4…
- CVE-2010-4509Multiple unspecified vulnerabilities in Movable Type 4.x bef…
- CVE-2010-4510Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2010-4511Unspecified vulnerability in Movable Type 4.x before 4.35 an…
- CVE-2010-4512Cobbler before 2.0.4 uses an incorrect umask value, which al…
Are you affected by CVE-2010-4506?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
