Polar Helpdesk Cookie Based Authentication System Bypass Vulnerability
BID:10775
Info
Polar Helpdesk Cookie Based Authentication System Bypass Vulnerability
| Bugtraq ID: | 10775 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2004 12:00AM |
| Updated: | Jul 21 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Noam Rathaus. |
| Vulnerable: |
Polar HelpDesk 3.0 |
| Not Vulnerable: | |
Discussion
Polar Helpdesk Cookie Based Authentication System Bypass Vulnerability
Polar Helpdesk is reported prone to a cookie based authentication system bypass vulnerability. It is reported that the authentication and privilege system for Polar Helpdesk is based entirely on the values read from a cookie that is saved on the client system. An attacker may modify values in the appropriate cookie to gain administrative access to the affected software.
Polar Helpdesk is reported prone to a cookie based authentication system bypass vulnerability. It is reported that the authentication and privilege system for Polar Helpdesk is based entirely on the values read from a cookie that is saved on the client system. An attacker may modify values in the appropriate cookie to gain administrative access to the affected software.
Exploit / POC
Polar Helpdesk Cookie Based Authentication System Bypass Vulnerability
The following examples are available:
HelpDesk_User=UserType=6&UserID=1
The following examples are available:
HelpDesk_User=UserType=6&UserID=1
Solution / Fix
Polar Helpdesk Cookie Based Authentication System Bypass Vulnerability
Solution:
It is reported that this vulnerability is addressed in the current build of Polar HelpDesk. This is not confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It is reported that this vulnerability is addressed in the current build of Polar HelpDesk. This is not confirmed.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Polar Helpdesk Cookie Based Authentication System Bypass Vulnerability
References:
References:
- HelpDesk Homepage (Polar)