PHProjekt Unspecified Authentication Bypass Vulnerability
BID:11797
Info
PHProjekt Unspecified Authentication Bypass Vulnerability
| Bugtraq ID: | 11797 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2004 12:00AM |
| Updated: | Dec 02 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Martin Münch. |
| Vulnerable: |
PHProjekt PHProjekt 4.2 PHProjekt PHProjekt 3.2 PHProjekt PHProjekt 3.1 a PHProjekt PHProjekt 3.1 PHProjekt PHProjekt 3.0 PHProjekt PHProjekt 2.4 a PHProjekt PHProjekt 2.4 PHProjekt PHProjekt 2.3 PHProjekt PHProjekt 2.2 PHProjekt PHProjekt 2.1 a PHProjekt PHProjekt 2.1 PHProjekt PHProjekt 2.0.1 PHProjekt PHProjekt 2.0 Gentoo Linux |
| Not Vulnerable: | |
Discussion
PHProjekt Unspecified Authentication Bypass Vulnerability
PHPProject is reported prone to an unspecified authentication bypass vulnerability. Reports indicate that the vulnerability is present in the 'setup.php' source file and may be exploited by a remote attacker to gain access to the 'setup.php' file without requiring authentication.
PHPProject is reported prone to an unspecified authentication bypass vulnerability. Reports indicate that the vulnerability is present in the 'setup.php' source file and may be exploited by a remote attacker to gain access to the 'setup.php' file without requiring authentication.
Exploit / POC
PHProjekt Unspecified Authentication Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PHProjekt Unspecified Authentication Bypass Vulnerability
Solution:
An updated 'setup.php' file is available to resolve this issue. The vendor advises that this file should be unpacked and should be used to replace the 'setup.php' file in the root directory of the installation:
http://phprojekt.com/files/4.2/setup.zip
Gentoo Linux has released an advisory (GLSA 200412-06) and an updated eBuild to address this vulnerability. As a superuser, Gentoo users are advised to execute the following commands in order to apply these updates:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/phprojekt-4.2-r1"
SuSE Linux has released a summary report dealing with this issue. Please see the referenced advisory and contact the vendor for information on obtaining the updated packages.
Solution:
An updated 'setup.php' file is available to resolve this issue. The vendor advises that this file should be unpacked and should be used to replace the 'setup.php' file in the root directory of the installation:
http://phprojekt.com/files/4.2/setup.zip
Gentoo Linux has released an advisory (GLSA 200412-06) and an updated eBuild to address this vulnerability. As a superuser, Gentoo users are advised to execute the following commands in order to apply these updates:
emerge --sync
emerge --ask --oneshot --verbose ">=www-apps/phprojekt-4.2-r1"
SuSE Linux has released a summary report dealing with this issue. Please see the referenced advisory and contact the vendor for information on obtaining the updated packages.
References
PHProjekt Unspecified Authentication Bypass Vulnerability
References:
References:
- PHProjekt Homepage (PHProjekt Team)
- Security hole in setup routine! (PHProjekt Team)