EmuLive Server4 Authentication Bypass And Denial Of Service Vulnerabilities
BID:11226
Info
EmuLive Server4 Authentication Bypass And Denial Of Service Vulnerabilities
| Bugtraq ID: | 11226 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 21 2004 12:00AM |
| Updated: | Sep 21 2004 12:00AM |
| Credit: | These issues were disclosed by James Bercegay. |
| Vulnerable: |
EmuLive Server4 |
| Not Vulnerable: | |
Discussion
EmuLive Server4 Authentication Bypass And Denial Of Service Vulnerabilities
Reportedly EmuLive Server4 is affected by an authentication bypass vulnerability and a denial of service vulnerability. These issues are due to an access validation issue and a failure to handle exceptional conditions.
An attacker may leverage the authentication bypass issue to gain unauthorized access to the administrator scripts of the affected application, facilitating manipulation of various server settings. The denial of service issue may be exploited to cause the affected computer to freeze, denying service to legitimate users.
Reportedly EmuLive Server4 is affected by an authentication bypass vulnerability and a denial of service vulnerability. These issues are due to an access validation issue and a failure to handle exceptional conditions.
An attacker may leverage the authentication bypass issue to gain unauthorized access to the administrator scripts of the affected application, facilitating manipulation of various server settings. The denial of service issue may be exploited to cause the affected computer to freeze, denying service to legitimate users.
Exploit / POC
EmuLive Server4 Authentication Bypass And Denial Of Service Vulnerabilities
No exploit is required to leverage either of these issues. The following is a proof of concept URI request designed to bypass the administrator authentication:
http://www.example.com//PUBLIC/ADMIN/INDEX.HTM
Note that the '//' after the 'http://www.example.com' is where a session ID would be presented, by providing no data between these slashes a NULL session ID is used to authenticate the attacker.
No exploit is required to leverage either of these issues. The following is a proof of concept URI request designed to bypass the administrator authentication:
http://www.example.com//PUBLIC/ADMIN/INDEX.HTM
Note that the '//' after the 'http://www.example.com' is where a session ID would be presented, by providing no data between these slashes a NULL session ID is used to authenticate the attacker.
Solution / Fix
EmuLive Server4 Authentication Bypass And Denial Of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EmuLive Server4 Authentication Bypass And Denial Of Service Vulnerabilities
References:
References:
- Server4 Home Page (EmuLive)
- Multiple Vulnerabilities In EmuLive Server4 ("GulfTech Security"
)