LinksCaffe CVE-2006-4462 Authentication Bypass Vulnerability
BID:19763
Info
LinksCaffe CVE-2006-4462 Authentication Bypass Vulnerability
| Bugtraq ID: | 19763 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4462 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2006 12:00AM |
| Updated: | Jul 05 2016 09:29PM |
| Credit: | HoangYenXinhDep of Vietnam Security Team discovered these vulnerabilities. |
| Vulnerable: |
Gonafish.com LinksCaffe 3.0 Gonafish.com LinksCaffe 2.0 |
| Not Vulnerable: | |
Discussion
LinksCaffe CVE-2006-4462 Authentication Bypass Vulnerability
LinksCaffe is prone to an authentication-bypass vulnerability because of a lack of required authentication on the application's administrative script. An attacker can use administrative functions simply by knowing the script's name and location.
A successful exploit of this issue could allow an attacker to compromise the application, access or modify data, delete site content, or exploit vulnerabilities in the system or underlying database implementation. Other attacks are also possible.
Versions 2.0 and 3.0 are reported vulnerable; other versions may also be affected.
LinksCaffe is prone to an authentication-bypass vulnerability because of a lack of required authentication on the application's administrative script. An attacker can use administrative functions simply by knowing the script's name and location.
A successful exploit of this issue could allow an attacker to compromise the application, access or modify data, delete site content, or exploit vulnerabilities in the system or underlying database implementation. Other attacks are also possible.
Versions 2.0 and 3.0 are reported vulnerable; other versions may also be affected.
Exploit / POC
LinksCaffe CVE-2006-4462 Authentication Bypass Vulnerability
Attackers can exploit these issues via a web client.
A proof-of-concept URI is provided:
Attackers can exploit these issues via a web client.
A proof-of-concept URI is provided:
Solution / Fix
LinksCaffe CVE-2006-4462 Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
LinksCaffe CVE-2006-4462 Authentication Bypass Vulnerability
References:
References:
- LinksCaffe 'admin1953.php' Grants Remote Users Administrative Access (HoangYenXinhDep of Vietnam Security Team)
- Vendor Homepage (Gonafish)