Web Dictate Admin Authentication Bypass Vulnerability
BID:19836
CVE-2006-4603 |Info
Web Dictate Admin Authentication Bypass Vulnerability
| Bugtraq ID: | 19836 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 04 2006 12:00AM |
| Updated: | Oct 19 2006 06:03PM |
| Credit: | Revnic Vasile has been credited with the discovery of this vulnerability. |
| Vulnerable: |
NCH Software Web Dictate 1.02 |
| Not Vulnerable: | |
Discussion
Web Dictate Admin Authentication Bypass Vulnerability
Web Dictate is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain administrative access to the affected application. This may lead to other attacks.
The vendor reports that only the beta version 1.02 is vulnerable to this issue.
Web Dictate is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain administrative access to the affected application. This may lead to other attacks.
The vendor reports that only the beta version 1.02 is vulnerable to this issue.
Exploit / POC
Web Dictate Admin Authentication Bypass Vulnerability
Attackers can exploit these issues via a web client.
Attackers can exploit these issues via a web client.
Solution / Fix
Web Dictate Admin Authentication Bypass Vulnerability
Solution:
The vendor released updates that address this issue. Please see the references section for further information.
Solution:
The vendor released updates that address this issue. Please see the references section for further information.
References
Web Dictate Admin Authentication Bypass Vulnerability
References:
References:
- NCH Homepage (NCH Software)
- Web Dictate Homepage (NCH Swift Sound)
- Web Dictate Admin Null Password Vulnerability ([email protected])