CVE-2008-7050
Summary
| CVE | CVE-2008-7050 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-08-24 10:30:02 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The password_check function in auth/auth_phpbb3.php in WoW Raid Manager 3.5.1 before Patch 1, when using PHPBB3 authentication, (1) does not invoke the CheckPassword function with the required arguments, which always triggers an authentication failure, and (2) returns true instead of false when an authentication failure occurs, which allows remote attackers to bypass authentication and gain privileges with an arbitrary password. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Wowraidmanager | Wowraidmanager | 3.1.0 | All | All | All |
| Application | Wowraidmanager | Wowraidmanager | 3.1.1 | All | All | All |
| Application | Wowraidmanager | Wowraidmanager | 3.1.2 | All | All | All |
| Application | Wowraidmanager | Wowraidmanager | 3.2.0 | All | All | All |
| Application | Wowraidmanager | Wowraidmanager | 3.2.1 | All | All | All |
| Application | Wowraidmanager | Wowraidmanager | 3.5.0 | All | All | All |
| Application | Wowraidmanager | Wowraidmanager | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Account Suspended | af854a3a-2127-422b-91ae-364da2661108 | www.wowraidmanager.net | Vendor Advisory |
| WOW Raid Manager "auth_phpbb3.php" Authentication Bypass - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| www.osvdb.org/49704 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Bug Fix: Fixes problem with phpBB3 bridge allowing login with ANY pas… · Illydth/wowraidmanager@7dd6367 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| Account Suspended | af854a3a-2127-422b-91ae-364da2661108 | www.wowraidmanager.net | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.