Keene Digital Media Server Admin Authentication Bypass Vulnerability
BID:11112
Info
Keene Digital Media Server Admin Authentication Bypass Vulnerability
| Bugtraq ID: | 11112 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 04 2004 12:00AM |
| Updated: | Sep 04 2004 12:00AM |
| Credit: | Discovery is credited to dr_insane. |
| Vulnerable: |
Keene Digital Media Server 1.0.2 |
| Not Vulnerable: | |
Discussion
Keene Digital Media Server Admin Authentication Bypass Vulnerability
Keene Digital Server is prone to an authentication bypass vulnerability. It is reported that remote unprivileged user may access administration pages without needing to authenticate as an administrator.
This may allow for unauthorized administrative actions.
This issue appears similar to one of the issues described in BID 10933 "Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities".
Keene Digital Server is prone to an authentication bypass vulnerability. It is reported that remote unprivileged user may access administration pages without needing to authenticate as an administrator.
This may allow for unauthorized administrative actions.
This issue appears similar to one of the issues described in BID 10933 "Keene Digital Media Server Directory Traversal and Authentication Bypass Vulnerabilities".
Exploit / POC
Keene Digital Media Server Admin Authentication Bypass Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Keene Digital Media Server Admin Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Keene Digital Media Server Admin Authentication Bypass Vulnerability
References:
References:
- Digital Media Server Home Page (Keene)