Hesk Admin.PHP Authentication Bypass Vulnerability
BID:14692
Info
Hesk Admin.PHP Authentication Bypass Vulnerability
| Bugtraq ID: | 14692 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2005 12:00AM |
| Updated: | Aug 29 2005 12:00AM |
| Credit: | HACKERS PAL is credited with the discovery of this vulnerability. |
| Vulnerable: |
Hesk Hesk 0.92 |
| Not Vulnerable: | |
Discussion
Hesk Admin.PHP Authentication Bypass Vulnerability
Hesk is prone to an authentication bypass vulnerability.
The application does not properly validate username and password pairs, and subsequently allows administrative access without a password.
This can lead to unauthorized access of sensitive data, modification of helpdesk data and program code, and other types of attacks.
Hesk is prone to an authentication bypass vulnerability.
The application does not properly validate username and password pairs, and subsequently allows administrative access without a password.
This can lead to unauthorized access of sensitive data, modification of helpdesk data and program code, and other types of attacks.
Exploit / POC
Hesk Admin.PHP Authentication Bypass Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Hesk Admin.PHP Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Hesk Admin.PHP Authentication Bypass Vulnerability
References:
References: