PHPStat Setup.PHP Authentication Bypass Vulnerability
BID:13786
Info
PHPStat Setup.PHP Authentication Bypass Vulnerability
| Bugtraq ID: | 13786 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2005 12:00AM |
| Updated: | May 27 2005 12:00AM |
| Credit: | SoulBlack - Security Research - is credited with the discovery of this vulnerability. |
| Vulnerable: |
phpStat phpStat 1.5 |
| Not Vulnerable: | |
Discussion
PHPStat Setup.PHP Authentication Bypass Vulnerability
phpStat is prone to an authentication bypass vulnerability. The issue presents itself when the application permits an unauthenticated remote user to reset the administrator username and password.
An attacker could exploit this vulnerability to gain administrative access to the affected application. This may also aid in further attacks against the underlying system.
phpStat is prone to an authentication bypass vulnerability. The issue presents itself when the application permits an unauthenticated remote user to reset the administrator username and password.
An attacker could exploit this vulnerability to gain administrative access to the affected application. This may also aid in further attacks against the underlying system.
Exploit / POC
PHPStat Setup.PHP Authentication Bypass Vulnerability
No exploit is required.
The following proof of concept exploit is available:
No exploit is required.
The following proof of concept exploit is available:
Solution / Fix
PHPStat Setup.PHP Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPStat Setup.PHP Authentication Bypass Vulnerability
References:
References:
- PHP Stat Administrative User Authentication Bypass (SoulBlack - Security Research -)
- phpStat Homepage (phpStat)