EQDKP Login.PHP Arbitrary Variable Overwrite Vulnerability
BID:24643
Info
EQDKP Login.PHP Arbitrary Variable Overwrite Vulnerability
| Bugtraq ID: | 24643 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2007 12:00AM |
| Updated: | Jul 03 2007 10:37PM |
| Credit: | kefka is credited with the discovery of this vulnerability. |
| Vulnerable: |
EQdkp EQdkp 1.3.2 EQdkp EQdkp 1.3.1 -p1 EQdkp EQdkp 1.3.1 EQdkp EQdkp 1.3 p4 EQdkp EQdkp 1.3 .0 EQdkp EQdkp 1.2 .0 EQdkp EQdkp 1.1 .0 EQdkp EQdkp 1.3.2e EQdkp EQdkp 1.3.2d EQdkp EQdkp 1.3.2c |
| Not Vulnerable: | |
Discussion
EQDKP Login.PHP Arbitrary Variable Overwrite Vulnerability
EQdkp is prone to a vulnerability that permits an attacker to overwrite arbitrary variables because of a design error.
Successful exploits will result in the compromise of vulnerable applications or denial-of-service conditions; other attacks are possible.
EQdkp 1.3.2e and prior versions are vulnerable.
EQdkp is prone to a vulnerability that permits an attacker to overwrite arbitrary variables because of a design error.
Successful exploits will result in the compromise of vulnerable applications or denial-of-service conditions; other attacks are possible.
EQdkp 1.3.2e and prior versions are vulnerable.
Exploit / POC
EQDKP Login.PHP Arbitrary Variable Overwrite Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
EQDKP Login.PHP Arbitrary Variable Overwrite Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].