EQDKP Backup.PHP Authentication Bypass Vulnerability
BID:20805
Info
EQDKP Backup.PHP Authentication Bypass Vulnerability
| Bugtraq ID: | 20805 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-0760 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 30 2006 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | Hofnar has been credited with the discovery of this vulnerability. |
| Vulnerable: |
EQdkp EQdkp 1.3.1 -p1 EQdkp EQdkp 1.3.1 EQdkp EQdkp 1.3 p4 EQdkp EQdkp 1.3 .0 EQdkp EQdkp 1.2 .0 EQdkp EQdkp 1.1 .0 |
| Not Vulnerable: | |
Discussion
EQDKP Backup.PHP Authentication Bypass Vulnerability
EQDKP is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to manipulate sensitive data and gain administrative access to the affected application; this may aid in further attacks.
EQDKP 1.3.1 p1 and prior versions are vulnerable; other versions may also be affected.
EQDKP is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to manipulate sensitive data and gain administrative access to the affected application; this may aid in further attacks.
EQDKP 1.3.1 p1 and prior versions are vulnerable; other versions may also be affected.
Exploit / POC
EQDKP Backup.PHP Authentication Bypass Vulnerability
Attackers can exploit these issues via a web client.
The following attack example is available:
Attackers can exploit these issues via a web client.
The following attack example is available:
Solution / Fix
EQDKP Backup.PHP Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].