IFDate Administrative Authentication Bypass Vulnerability
BID:23971
Info
IFDate Administrative Authentication Bypass Vulnerability
| Bugtraq ID: | 23971 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-2713 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2007 12:00AM |
| Updated: | May 07 2015 05:39PM |
| Credit: | Discovery is credited to Liz0zim. |
| Vulnerable: |
iFusion iFdate 2.0.3 iFusion iFdate 2.0 |
| Not Vulnerable: | |
Discussion
IFDate Administrative Authentication Bypass Vulnerability
iFdate is prone to a vulnerability that will let attackers trivially gain administrative access to the application.
This issue stems from insufficient access validation.
iFdate 2.0 and later versions are vulnerable.
iFdate is prone to a vulnerability that will let attackers trivially gain administrative access to the application.
This issue stems from insufficient access validation.
iFdate 2.0 and later versions are vulnerable.
Exploit / POC
IFDate Administrative Authentication Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
IFDate Administrative Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
IFDate Administrative Authentication Bypass Vulnerability
References:
References: