ModernBill CVE-2006-4499 Remote Security Vulnerability

ModernBill is prone to a remote security vulnerability because it uses cURL with insecure settings for 'CURLOPT_SSL_VERIFYPEER' and 'CURLOPT_SSL_VERIFYHOST' that do not verify SSL certificates, which allows remote attackers to read network traffic via a man-in-the-middle (MITM) attack.


 

Privacy Statement
Copyright 2010, SecurityFocus