token-manipulation

1 article
sort: new top best
clear filter
0 7/10

Symantec Messaging Gateway contains an authentication bypass vulnerability in its password reset feature that uses weak static encryption (PBEWithMD5AndDES with hardcoded key) to protect tokens formatted as 'username:password'. An attacker can encrypt 'admin:' and pass it as the authorization parameter to gain valid administrator session access.

Symantec Messaging Gateway Artem Kondratenko Philip Pettersson SYMSA1461 PBEWithMD5AndDES SMG 10.6.5
artkond.com · devanshbatham/Awesome-Bugbounty-Writeups · 18 hours ago · details