MiniHTTPServer Web Forum and File Sharing Server Add User Authentication Bypass Vulnerability
BID:20743
Info
MiniHTTPServer Web Forum and File Sharing Server Add User Authentication Bypass Vulnerability
| Bugtraq ID: | 20743 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2006 12:00AM |
| Updated: | Dec 02 2006 12:49AM |
| Credit: | Greg Linares is credited with the discovery of this vulnerability. |
| Vulnerable: |
MiniHTTPServer Web Forum & File Sharing Server 4.0 |
| Not Vulnerable: | |
Discussion
MiniHTTPServer Web Forum and File Sharing Server Add User Authentication Bypass Vulnerability
MiniHTTPServer Web Forum and File Sharing Server is prone to an authentication-bypass vulnerability because the application fails to sanitize user-supplied input.
An attacker can exploit this issue to gain 'PowerUser' access (restricted administrative access) to the affected application. This may lead to other attacks.
This issue affects version 4.0; other versions may also be affected.
MiniHTTPServer Web Forum and File Sharing Server is prone to an authentication-bypass vulnerability because the application fails to sanitize user-supplied input.
An attacker can exploit this issue to gain 'PowerUser' access (restricted administrative access) to the affected application. This may lead to other attacks.
This issue affects version 4.0; other versions may also be affected.
Exploit / POC
MiniHTTPServer Web Forum and File Sharing Server Add User Authentication Bypass Vulnerability
Attackers can exploit these issues through a web client.
The following proof-of-concept URI is available:
Attackers can exploit these issues through a web client.
The following proof-of-concept URI is available:
Solution / Fix
MiniHTTPServer Web Forum and File Sharing Server Add User Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
A third-party fix is available to address this issue. Symantec has not confirmed the integrity of this patch.
Please see the references section for further information
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
A third-party fix is available to address this issue. Symantec has not confirmed the integrity of this patch.
Please see the references section for further information
References
MiniHTTPServer Web Forum and File Sharing Server Add User Authentication Bypass Vulnerability
References:
References:
- MiniHTTPd 4.0 Unofficial Patch (Tim Hentenaar)
- Vendor Home Page (MiniHTTPServer)