Eskuel Unauthorized Administrator Access Vulnerability
BID:14163
Info
Eskuel Unauthorized Administrator Access Vulnerability
| Bugtraq ID: | 14163 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2005 12:00AM |
| Updated: | Jul 06 2005 12:00AM |
| Credit: | Michael Hummel <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Eskuel Eskuel 1.0.2 |
| Not Vulnerable: | |
Discussion
Eskuel Unauthorized Administrator Access Vulnerability
Eskuel is prone to a vulnerability regarding the unauthorized access to administrator functions. This issue is due to a failure in the application to do proper authentication on user credentials before granting access to privileged sections of the application.
This issue could be exploited to elevate privileges, this could aid in further attacks against the underlying system; other attacks are also possible.
Eskuel is prone to a vulnerability regarding the unauthorized access to administrator functions. This issue is due to a failure in the application to do proper authentication on user credentials before granting access to privileged sections of the application.
This issue could be exploited to elevate privileges, this could aid in further attacks against the underlying system; other attacks are also possible.
Exploit / POC
Eskuel Unauthorized Administrator Access Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Eskuel Unauthorized Administrator Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Eskuel Unauthorized Administrator Access Vulnerability
References:
References:
- Debian Bug report logs - #163653 (Debian)