CVE-2012-1256
Easyvista < 2010 - Authentication Bypass
Title source: ruleDescription
The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account parameter, in conjunction with a valid login name in the SSPI_HEADER parameter, to index.php.
Scores
EPSS
0.0022
EPSS Percentile
44.7%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
easyvista/easyvista
< 2010
Timeline
Published
Feb 22, 2012
Tracked Since
Feb 18, 2026