password-reset-flaw

1 article
sort: new top best
clear filter
0 7/10

Symantec Messaging Gateway versions ≤10.6.5 contain an authentication bypass in the password reset feature due to encryption of password reset tokens using a hardcoded static key with weak PBEWithMD5AndDES cipher. An attacker can craft a valid administrator session by encrypting the string 'admin:' and passing it as an authorization parameter.

Symantec Messaging Gateway Artem Kondratenko Philip Pettersson SYMSA1461 PBEWithMD5AndDES
artkond.com · devanshbatham/Awesome-Bugbounty-Writeups · 18 hours ago · details