[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Authentication bypass vulnerability in .NET Framework - CVE-2013-1337

ID: oval:org.secpod.oval:def:10947Date: (C)2013-05-16   (M)2021-06-02
Class: VULNERABILITYFamily: windows




The host is installed with .NET Framework 4.5 and is prone to authentication bypass vulnerability. A flaw is present in the application, which fails to create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS. Successful exploitation allows attackers to bypass authentication by sending queries to an endpoint.

Platform:
Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Product:
Microsoft .NET Framework 4.5
Reference:
CVE-2013-1337
CVE    1
CVE-2013-1337
CPE    22
cpe:/o:microsoft:windows_server_2008:r2:sp1:x64
cpe:/o:microsoft:windows_server_2008:::x64
cpe:/o:microsoft:windows_server_2008:::x86
cpe:/o:microsoft:windows_7::sp1:x64
...

© SecPod Technologies