>> Check Point Connectra and VPN-1 Power/UTM Products Security Bypass Vulnerability
Title : Check Point Connectra and VPN-1 Power/UTM Products Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2007-0276 CVE ID : CVE-2007-0471
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-01-22
Technical Description
A vulnerability has been identified in Check Point Connectra and VPN-1 Power/UTM products, which could be exploited by attackers to bypass security restrictions. This issue is due to an input validation error in the "sre/params.php" script within the Integrity Clientless Security feature that fails to validate user-supplied reports before before granting access to a protected network, which could be exploited by malicious people to gain unauthorized access to a network via a specially crafted HTTP request.