Multiple RadScript Products Authentication Bypass Vulnerability
BID:19128
Info
Multiple RadScript Products Authentication Bypass Vulnerability
| Bugtraq ID: | 19128 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2006 12:00AM |
| Updated: | Jul 25 2006 06:52PM |
| Credit: | INVENT is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
RadScripts RadNics Gold 0 RadScripts RadLance Gold 7.0 RadScripts RadBids Gold v2 |
| Not Vulnerable: | |
Discussion
Multiple RadScript Products Authentication Bypass Vulnerability
Multiple Rad Scripts products are prone to an authentication-bypass vulnerability. These issues occur because the applications fail to prevent an attacker from accessing admin scripts directly without requiring authentication.
A remote attacker can exploit these issues to perform administrative functions without requiring authentication. For example, the attacker may be able to overwrite existing files on the vulnerable computer in the context of the webserver process.
Multiple Rad Scripts products are prone to an authentication-bypass vulnerability. These issues occur because the applications fail to prevent an attacker from accessing admin scripts directly without requiring authentication.
A remote attacker can exploit these issues to perform administrative functions without requiring authentication. For example, the attacker may be able to overwrite existing files on the vulnerable computer in the context of the webserver process.
Exploit / POC
Multiple RadScript Products Authentication Bypass Vulnerability
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
Solution / Fix
Multiple RadScript Products Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Multiple RadScript Products Authentication Bypass Vulnerability
References:
References:
- RadScripts Homepage (RadScripts)