Security Advisory
CVE-2013-3499
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
GroundWork Monitor Enterprise 6.7.0 performs authentication on the basis of the HTTP Referer header, which allows remote attackers to obtain administrative privileges or access files via a crafted header.