Mensajeitor Tag Board Authentication Bypass Vulnerability
BID:10774
Info
Mensajeitor Tag Board Authentication Bypass Vulnerability
| Bugtraq ID: | 10774 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2004 12:00AM |
| Updated: | Jul 21 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Jordi Corrales <[email protected]>. |
| Vulnerable: |
Mensajeitor Tag Board 1.8.9 r1 Mensajeitor Tag Board 1.8.9 Mensajeitor Tag Board 1.8.6 r2 Mensajeitor Tag Board 1.8.6 Mensajeitor Tag Board 1.8.5 Mensajeitor Tag Board 1.8 Mensajeitor Tag Board 1.7 Mensajeitor Tag Board 1.6.5 Mensajeitor Tag Board 1.6.1 Mensajeitor Tag Board 1.6 Mensajeitor Tag Board 1.5.2 Mensajeitor Tag Board 1.5 PE Mensajeitor Tag Board 1.5 Mensajeitor Tag Board 1.4 b Mensajeitor Tag Board 1.3 PE Mensajeitor Tag Board 1.3 Mensajeitor Tag Board 1.0 |
| Not Vulnerable: | |
Discussion
Mensajeitor Tag Board Authentication Bypass Vulnerability
It has been reported that Mensajeitor Tag Board is affected by an authentication bypass vulnerability. This issue is due to a failure of the application to properly handle authentication controls.
Successful exploitation of this issue will allow an attacker to post messages to the affected tag board as an administrator, reportedly facilitating HTML injection and attacks.
It has been reported that Mensajeitor Tag Board is affected by an authentication bypass vulnerability. This issue is due to a failure of the application to properly handle authentication controls.
Successful exploitation of this issue will allow an attacker to post messages to the affected tag board as an administrator, reportedly facilitating HTML injection and attacks.
Exploit / POC
Mensajeitor Tag Board Authentication Bypass Vulnerability
No exploit is required to leverage this issue. The following proof of concept has been provided:
No exploit is required to leverage this issue. The following proof of concept has been provided:
Solution / Fix
Mensajeitor Tag Board Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Mensajeitor Tag Board Authentication Bypass Vulnerability
References:
References:
- Inyección de código en 'Mensajeitor' <= 1.8.9 r1 (ShellSecurity)
- Mensajeitor Inadequate Permissions Check (SecuriTeam.com)
- Project Web Site (Mensajeitor)