Ragnarok Online Control Panel Authentication Bypass Vulnerability
BID:14429
Info
Ragnarok Online Control Panel Authentication Bypass Vulnerability
| Bugtraq ID: | 14429 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2005 12:00AM |
| Updated: | Jul 30 2005 12:00AM |
| Credit: | Discovery is credited to VaLiuS. |
| Vulnerable: |
Azndragon Ragnarok Online Control Panel 4.3.4 a |
| Not Vulnerable: | |
Discussion
Ragnarok Online Control Panel Authentication Bypass Vulnerability
Ragnarok Online Control Panel (ROCP) is prone to a vulnerability that may let remote attackers bypass user authentication. This issue is related to how PHP variables are handled, letting an attacker influence a variable that is used to check user authentication.
Exploitation could yield administrative access to the ROCP site.
This issue may be exclusive to sites hosting ROCP with Apache Web server. This has not been confirmed.
Ragnarok Online Control Panel (ROCP) is prone to a vulnerability that may let remote attackers bypass user authentication. This issue is related to how PHP variables are handled, letting an attacker influence a variable that is used to check user authentication.
Exploitation could yield administrative access to the ROCP site.
This issue may be exclusive to sites hosting ROCP with Apache Web server. This has not been confirmed.
Exploit / POC
Ragnarok Online Control Panel Authentication Bypass Vulnerability
The following example was provided:
http://www.example.com/CP/account_manage.php/login.php
The following example was provided:
http://www.example.com/CP/account_manage.php/login.php
Solution / Fix
Ragnarok Online Control Panel Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ragnarok Online Control Panel Authentication Bypass Vulnerability
References:
References: