Title: Allaire Spectra 1.0 Webtop Vulnerability
Severity: LOW
Description:
Allaire Spectra is a web-based e-commerce product. The Webtop portion of Spectra allows for the creation of customizable web interfaces for administration of the various services provided by the Spectra system. These interfaces can be tailored to provide seperate functionality for users with different roles in the administration and deployment of the product.
Due to an error in a configuration file shipped with Spectra, users who have access to only one part of the Webtop feature can gain access to all other Webtop enabled controls by typing in the explicit URL of those features. Note that to exploit this vulnerability the attacker must already have authorized access to at least one part of the Webtop interface.
Affected Products:
- Allaire Spectra 1.0.0
References:
- Allaire: Spectra Home Page
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.