TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2018-6651

N/A

Beschreibung

In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec, this means full control over the victim's computer.

CVE Details

CVSS v3.1 BewertungN/A
Veroffentlicht2/5/2018
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

parsecgaming:parsecuncurl_project:uncurl

Schwachen (CWE)

CWE-352

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.