PHP TopSites Setup.PHP Authentication Bypass Vulnerability
BID:14353
Info
PHP TopSites Setup.PHP Authentication Bypass Vulnerability
| Bugtraq ID: | 14353 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 22 2005 12:00AM |
| Updated: | Jul 22 2005 12:00AM |
| Credit: | h4cky0u and Donnie Werner are credited with the discovery of this vulnerability. |
| Vulnerable: |
PHP TopSites PRO PHP TopSites PRO 2.2 PHP Topsites FREE PHP Topsites FREE 2.2 |
| Not Vulnerable: | |
Discussion
PHP TopSites Setup.PHP Authentication Bypass Vulnerability
PHP TopSites is prone to an authentication bypass wulnerbility. An attacker may bypass authentication and gain access to the vulnerable application.
Once access has been achieved, the malicious user has full control of the application. This may aid in further attacks against the underlying system.
PHP TopSites is prone to an authentication bypass wulnerbility. An attacker may bypass authentication and gain access to the vulnerable application.
Once access has been achieved, the malicious user has full control of the application. This may aid in further attacks against the underlying system.
Exploit / POC
PHP TopSites Setup.PHP Authentication Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PHP TopSites Setup.PHP Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP TopSites Setup.PHP Authentication Bypass Vulnerability
References:
References:
- EXPL-A-2005-012 exploitlabs.com Advisory 041 (h4cky0u)
- PHP TopSites Website (PHP TopSites)