PHPTrafficA IsLoggedIn Function Authentication Bypass Vulnerability
BID:24823
Info
PHPTrafficA IsLoggedIn Function Authentication Bypass Vulnerability
| Bugtraq ID: | 24823 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-3647 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | CorryL is credited with the discovery of this vulnerability. |
| Vulnerable: |
phpTrafficA phpTrafficA 1.4.3 |
| Not Vulnerable: | |
Discussion
PHPTrafficA IsLoggedIn Function Authentication Bypass Vulnerability
PHPTrafficA is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain administrative access to the affected application.
This issue affects phpTrafficA 1.4.3; other versions may also be affected.
PHPTrafficA is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain administrative access to the affected application.
This issue affects phpTrafficA 1.4.3; other versions may also be affected.
Exploit / POC
PHPTrafficA IsLoggedIn Function Authentication Bypass Vulnerability
An attacker can exploit this issue by using standard network utilities.
An attacker can exploit this issue by using standard network utilities.
Solution / Fix
PHPTrafficA IsLoggedIn Function Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHPTrafficA IsLoggedIn Function Authentication Bypass Vulnerability
References:
References:
- phpTrafficA <=1.4.3 Admin Login Bypass (Corryl )
- phpTrafficA Home Page (phpTrafficA)