OpenDocMan Access Control Bypass Vulnerability
BID:10807
Info
OpenDocMan Access Control Bypass Vulnerability
| Bugtraq ID: | 10807 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2004 12:00AM |
| Updated: | Jul 26 2004 12:00AM |
| Credit: | The vendor disclosed this vulnerability. |
| Vulnerable: |
OpenDocMan OpenDocMan 1.1 OpenDocMan OpenDocMan 1.0 |
| Not Vulnerable: |
OpenDocMan OpenDocMan 1.2 |
Discussion
OpenDocMan Access Control Bypass Vulnerability
It is reported that OpenDocMan contains an access bypass vulnerability.
This vulnerability could be exploited to create, update, or delete users, departments or categories without proper authorization.
An attacker requires an account in the application. Once logged into the application, they can issue requests to the vulnerable script and commit changes that only the administrator should be able to do.
By exploiting this vulnerability, an attacker can gain administrator privileges in the application. They could also delete all user accounts, denying access to legitimate users. Other attacks are possible.
Versions prior to 1.2 are reported vulnerable.
It is reported that OpenDocMan contains an access bypass vulnerability.
This vulnerability could be exploited to create, update, or delete users, departments or categories without proper authorization.
An attacker requires an account in the application. Once logged into the application, they can issue requests to the vulnerable script and commit changes that only the administrator should be able to do.
By exploiting this vulnerability, an attacker can gain administrator privileges in the application. They could also delete all user accounts, denying access to legitimate users. Other attacks are possible.
Versions prior to 1.2 are reported vulnerable.
Exploit / POC
OpenDocMan Access Control Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
OpenDocMan Access Control Bypass Vulnerability
Solution:
The vendor has released version 1.2 addressing this vulnerability.
OpenDocMan OpenDocMan 1.0
OpenDocMan OpenDocMan 1.1
Solution:
The vendor has released version 1.2 addressing this vulnerability.
OpenDocMan OpenDocMan 1.0
-
OpenDocMan opendocman-1.2.tar.gz
http://prdownloads.sourceforge.net/opendocman/opendocman-1.2.tar.gz?do wnload
OpenDocMan OpenDocMan 1.1
-
OpenDocMan opendocman-1.2.tar.gz
http://prdownloads.sourceforge.net/opendocman/opendocman-1.2.tar.gz?do wnload
References
OpenDocMan Access Control Bypass Vulnerability
References:
References:
- OpenDocMan Homepage (OpenDocMan)
- OpenDocMan release 1.2 changelog (OpenDocMan)