CVE-2012-1256

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
22/02/2012
Last modified:
11/04/2025

Description

The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account parameter, in conjunction with a valid login name in the SSPI_HEADER parameter, to index.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:easyvista:easyvista:*:*:*:*:*:*:*:* 2010 (including)