WebSPELL Database.PHP Authentication Bypass Vulnerability
BID:19975
CVE-2006-4782 |Info
WebSPELL Database.PHP Authentication Bypass Vulnerability
| Bugtraq ID: | 19975 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4782 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2006 12:00AM |
| Updated: | Jul 06 2007 07:47PM |
| Credit: | Trex is credited with the discovery of this vulnerability. |
| Vulnerable: |
webSPELL webSPELL 4.1.1 webSPELL webSPELL 4.1 webSPELL webSPELL 4.0 |
| Not Vulnerable: | |
Discussion
WebSPELL Database.PHP Authentication Bypass Vulnerability
webSPELL is prone to an authentication-bypass vulnerability because it fails to sufficiently sanitize user-supplied data.
This issue may allow an attacker to bypass the authentication mechanism and allow unauthorized access to the affected application. This may lead to other attacks.
webSPELL 4.01.01 and prior versions are affected by this issue.
webSPELL is prone to an authentication-bypass vulnerability because it fails to sufficiently sanitize user-supplied data.
This issue may allow an attacker to bypass the authentication mechanism and allow unauthorized access to the affected application. This may lead to other attacks.
webSPELL 4.01.01 and prior versions are affected by this issue.
Exploit / POC
WebSPELL Database.PHP Authentication Bypass Vulnerability
An attacker can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/[PATH]/admin/database.php?action=write&userID=1
Trex
An attacker can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/[PATH]/admin/database.php?action=write&userID=1
Trex
Solution / Fix
WebSPELL Database.PHP Authentication Bypass Vulnerability
Solution:
The vendor has released Security Fix 2006-09-11 to address this issue.
Please see the references for more information.
webSPELL webSPELL 4.0
webSPELL webSPELL 4.1
webSPELL webSPELL 4.1.1
Solution:
The vendor has released Security Fix 2006-09-11 to address this issue.
Please see the references for more information.
webSPELL webSPELL 4.0
-
webSPELL webSPELL Security Fix 2006-09-11
http://cms.webspell.org/index.php?site=files&file=15
webSPELL webSPELL 4.1
-
webSPELL webSPELL Security Fix 2006-09-11
http://cms.webspell.org/index.php?site=files&file=15
webSPELL webSPELL 4.1.1
-
webSPELL webSPELL Security Fix 2006-09-11
http://cms.webspell.org/index.php?site=files&file=15