DownFile Administrator Unauthorized Access Vulnerability
BID:14714
Info
DownFile Administrator Unauthorized Access Vulnerability
| Bugtraq ID: | 14714 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2005 12:00AM |
| Updated: | Sep 01 2005 12:00AM |
| Credit: | benozor77 is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Eric Fichot DownFile 1.3 |
| Not Vulnerable: | |
Discussion
DownFile Administrator Unauthorized Access Vulnerability
DownFile is prone to an unauthorized access vulnerability. This issue is due to a failure in the application to perform proper authentication before granting access to administrative functions.
An attacker can exploit this vulnerability to gain access to administrative functions, this will result in an elevation of privileges.
DownFile is prone to an unauthorized access vulnerability. This issue is due to a failure in the application to perform proper authentication before granting access to administrative functions.
An attacker can exploit this vulnerability to gain access to administrative functions, this will result in an elevation of privileges.
Exploit / POC
DownFile Administrator Unauthorized Access Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
DownFile Administrator Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
DownFile Administrator Unauthorized Access Vulnerability
References:
References:
- DownFile Documentation (Eric Fichot)