phpMyFAQ Image Manager Authentication Bypass Vulnerability
BID:10813
Info
phpMyFAQ Image Manager Authentication Bypass Vulnerability
| Bugtraq ID: | 10813 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 27 2004 12:00AM |
| Updated: | Jul 27 2004 12:00AM |
| Credit: | This vulnerability was reported by the vendor. |
| Vulnerable: |
phpMyFAQ phpMyFAQ 1.4 -alpha 2 phpMyFAQ phpMyFAQ 1.4 -alpha 1 phpMyFAQ phpMyFAQ 1.4 |
| Not Vulnerable: |
phpMyFAQ phpMyFAQ 1.4 a |
Discussion
phpMyFAQ Image Manager Authentication Bypass Vulnerability
It is reported that phpMyFAQ contains an authentication bypass vulnerability in its image manager.
This vulnerability can be exploited by remote anonymous attackers to upload or delete images in the phpMyFAQ application without authorization.
A remote attacker could deface the application, or delete all images in the database.
Version 1.4 is reported vulnerable. The vendor has released version 1.4a that corrects this issue.
It is reported that phpMyFAQ contains an authentication bypass vulnerability in its image manager.
This vulnerability can be exploited by remote anonymous attackers to upload or delete images in the phpMyFAQ application without authorization.
A remote attacker could deface the application, or delete all images in the database.
Version 1.4 is reported vulnerable. The vendor has released version 1.4a that corrects this issue.
Exploit / POC
phpMyFAQ Image Manager Authentication Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
phpMyFAQ Image Manager Authentication Bypass Vulnerability
Solution:
The vendor has released an advisory and a new version of the application dealing with this issue. Please see the referenced advisory for further information.
Solution:
The vendor has released an advisory and a new version of the application dealing with this issue. Please see the referenced advisory for further information.
References
phpMyFAQ Image Manager Authentication Bypass Vulnerability
References:
References:
- phpMyFAQ Homepage (phpMyFAQ)
- Security Advisory - Vulnerability in phpMyFAQ version 1.4.0 (phpMyFAQ)