ABB Cylon Aspect version 3.08.01 is vulnerable to an unauthorized project file disclosure in jsonProxy.php. An unauthenticated remote attacker can issue a GET request abusing the DownloadProject servlet to download sensitive project files. The jsonProxy.php script bypasses authentication by proxying requests to localhost (AspectFT Automation...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #2388144
💾 ABB Cylon Aspect 3.08.01 jsonProxy.php Unauthenticated Project Download
⏱️ vor 635d 2h (30.10.2024 um 16:26 Uhr) 📂 💾 IT Security Tools 📡 Feed 🔗 Quelle: packetstormsecurity.com