Sense of Security FileBound Privilege Escalation Vulnerability
19 Oct. 2012
Summary
The FileBound On-Site document management application is vulnerable to a privilege escalation attack by sending a modified password request to the FileBound web service. By modifying the UserID value you can reset the password of any local user in the application without requiring administrative privileges.
Credit:
The information has been provided by Nathaniel Carew from Sense of Security Labs..
By modifying the UserID value the password can be reset for
any existing user in the system. A response code of -1 confirms the password reset was successful.