SAPID CMS Authentication Bypass Vulnerability
BID:15689
Info
SAPID CMS Authentication Bypass Vulnerability
| Bugtraq ID: | 15689 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Dec 02 2005 12:00AM |
| Updated: | Dec 02 2005 12:00AM |
| Credit: | This vulnerabibility was reported by the vendor. |
| Vulnerable: |
Sapid CMS 1.2.3 RC2 Sapid CMS 1.2.3 |
| Not Vulnerable: |
Sapid CMS 1.2.3 RC3 |
Discussion
SAPID CMS Authentication Bypass Vulnerability
SAPID CMS is prone to an authentication bypass vulnerability. This issue is due to a failure in the application to perform proper authentication on user credentials before granting access to privileged scripts.
An attacker can exploit this vulnerability to access privileged scripts without requiring authentication credentials.
SAPID CMS is prone to an authentication bypass vulnerability. This issue is due to a failure in the application to perform proper authentication on user credentials before granting access to privileged scripts.
An attacker can exploit this vulnerability to access privileged scripts without requiring authentication credentials.
Exploit / POC
SAPID CMS Authentication Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
SAPID CMS Authentication Bypass Vulnerability
Solution:
The vendor has released version 1.2.3 RC3 to address this issue.
Sapid CMS 1.2.3 RC2
Sapid CMS 1.2.3
Solution:
The vendor has released version 1.2.3 RC3 to address this issue.
Sapid CMS 1.2.3 RC2
-
Sapid sapid_v123_rc3.zip
http://prdownloads.sourceforge.net/sapid/sapid_v123_rc3.zip
Sapid CMS 1.2.3
-
Sapid sapid_v123_rc3.zip
http://prdownloads.sourceforge.net/sapid/sapid_v123_rc3.zip
References
SAPID CMS Authentication Bypass Vulnerability
References:
References:
- Sapid CMS very important security update. (Sapid CMS)
- Sapid Download Web Site (Sapid )