SurgeLDAP Web Administration Authentication Bypass Vulnerability
BID:10294
Info
SurgeLDAP Web Administration Authentication Bypass Vulnerability
| Bugtraq ID: | 10294 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 05 2004 12:00AM |
| Updated: | May 05 2004 12:00AM |
| Credit: | GSS IT <[email protected]> is credited for finding this vulnerability. |
| Vulnerable: |
NetWin SurgeLDAP 1.0 g NetWin SurgeLDAP 1.0 f NetWin SurgeLDAP 1.0 e NetWin SurgeLDAP 1.0 d NetWin SurgeLDAP 1.0 b NetWin SurgeLDAP 1.0 a |
| Not Vulnerable: | |
Discussion
SurgeLDAP Web Administration Authentication Bypass Vulnerability
SurgeLDAP is an LDAP server implementation for Microsoft Windows and various Unix operating systems. It includes a built-in web server to permit remote user access via HTTP.
It has been reported that the SurgeLDAP web administration application is prone to an authentication bypass vulnerability, possibly allowing remote attackers manager access.
Once administration access is granted, it may be possible for an attacker to modify records in the LDAP database, destroy data, crash the server, or possibly further attacks on other services utilizing SurgeLDAP for it's authentication data.
SurgeLDAP is an LDAP server implementation for Microsoft Windows and various Unix operating systems. It includes a built-in web server to permit remote user access via HTTP.
It has been reported that the SurgeLDAP web administration application is prone to an authentication bypass vulnerability, possibly allowing remote attackers manager access.
Once administration access is granted, it may be possible for an attacker to modify records in the LDAP database, destroy data, crash the server, or possibly further attacks on other services utilizing SurgeLDAP for it's authentication data.
Exploit / POC
SurgeLDAP Web Administration Authentication Bypass Vulnerability
No exploit is required, but the following example URI was disclosed:
http://www.example.com/admin.cgi?cmd=show&page=main.tpl&utoken=manager
No exploit is required, but the following example URI was disclosed:
http://www.example.com/admin.cgi?cmd=show&page=main.tpl&utoken=manager
Solution / Fix
SurgeLDAP Web Administration Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SurgeLDAP Web Administration Authentication Bypass Vulnerability
References:
References:
- SurgeLDAP Homepage (NetWin)