AR-Blog Remote Authentication Bypass Vulnerability
BID:15203
Info
AR-Blog Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 15203 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2005 12:00AM |
| Updated: | Oct 25 2005 12:00AM |
| Credit: | _MoHaJaLi_ is credited with the discovery of this vulnerability. |
| Vulnerable: |
ar-blog ar-blog 5.2 ar-blog ar-blog 2.0 |
| Not Vulnerable: | |
Discussion
AR-Blog Remote Authentication Bypass Vulnerability
ar-blog is prone to an authentication bypass vulnerability.
An attacker may bypass the authentication process and make changes to posts with the effective rights of the Web log administrator.
Version 5.2 and prior are reported to be vulnerable.
ar-blog is prone to an authentication bypass vulnerability.
An attacker may bypass the authentication process and make changes to posts with the effective rights of the Web log administrator.
Version 5.2 and prior are reported to be vulnerable.
Exploit / POC
AR-Blog Remote Authentication Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
AR-Blog Remote Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.