Simple CMS Auth.PHP Remote Authentication Bypass Vulnerability
BID:19386
Info
Simple CMS Auth.PHP Remote Authentication Bypass Vulnerability
| Bugtraq ID: | 19386 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2006 12:00AM |
| Updated: | Aug 08 2006 05:00PM |
| Credit: | [email protected] reported this vulnerability. |
| Vulnerable: |
Simple CMS Simple CMS 0 |
| Not Vulnerable: | |
Discussion
Simple CMS Auth.PHP Remote Authentication Bypass Vulnerability
Simple CMS is prone to an authentication-bypass vulnerability because of a flaw in the authentication process of the affected package.
Exploiting this issue may allow attackers to gain unauthenticated, remote access to administrative sections of the application.
Simple CMS is prone to an authentication-bypass vulnerability because of a flaw in the authentication process of the affected package.
Exploiting this issue may allow attackers to gain unauthenticated, remote access to administrative sections of the application.
Exploit / POC
Simple CMS Auth.PHP Remote Authentication Bypass Vulnerability
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
Simple CMS Auth.PHP Remote Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Simple CMS Auth.PHP Remote Authentication Bypass Vulnerability
References:
References:
- Simple CMS Web Site (Simple CMS)