Belong Software Site Builder Administration Pages Authentication Bypass Vulnerability
BID:27402
Info
Belong Software Site Builder Administration Pages Authentication Bypass Vulnerability
| Bugtraq ID: | 27402 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-4585 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | RoMaNcYxHaCkEr is credited with the discovery of this issue. |
| Vulnerable: |
Belong Software Site Builder 0.1 beta |
| Not Vulnerable: | |
Discussion
Belong Software Site Builder Administration Pages Authentication Bypass Vulnerability
Belong Software Site Builder is prone to a vulnerability that results in unauthorized administrative access. The application fails to authenticate users when certain pages are accessed.
Attackers can leverage this issue to compromise the application, which could aid in other attacks.
Site Builder 0.1 beta is vulnerable; other versions may also be affected.
Belong Software Site Builder is prone to a vulnerability that results in unauthorized administrative access. The application fails to authenticate users when certain pages are accessed.
Attackers can leverage this issue to compromise the application, which could aid in other attacks.
Site Builder 0.1 beta is vulnerable; other versions may also be affected.
Exploit / POC
Belong Software Site Builder Administration Pages Authentication Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Belong Software Site Builder Administration Pages Authentication Bypass Vulnerability
Solution:
UPTATE (January 23, 2008): The vendor states that a fix for this issue will be released in the next few days. We will update this BID when the fix is available.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
UPTATE (January 23, 2008): The vendor states that a fix for this issue will be released in the next few days. We will update this BID when the fix is available.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Belong Software Site Builder Administration Pages Authentication Bypass Vulnerability
References:
References:
- Vendor Homepage (Belong Software)
- Belong Site Builder 0.1b Bypass Admincp (
)