zKup Authentication Bypass Vulnerability
BID:28149
Info
zKup Authentication Bypass Vulnerability
| Bugtraq ID: | 28149 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-7124 CVE-2008-7123 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | Charles "real" F. discovered this vulnerability. |
| Vulnerable: |
zKup zKup 2.03 zKup zKup 2.02 zKup zKup 2.01 zKup zKup 2.0 |
| Not Vulnerable: |
zKup zKup 2.04 |
Discussion
zKup Authentication Bypass Vulnerability
zKup is prone to a vulnerability that allows attackers to bypass authentication. This issue occurs because the application fails to authenticate administrative users.
Attackers can leverage this issue to gain unauthorized administrative access to the application and then possibly launch further attacks.
zKup is prone to a vulnerability that allows attackers to bypass authentication. This issue occurs because the application fails to authenticate administrative users.
Attackers can leverage this issue to gain unauthorized administrative access to the application and then possibly launch further attacks.
Exploit / POC
zKup Authentication Bypass Vulnerability
Attackers may exploit this issue through a browser.
The following exploit code is available:
Attackers may exploit this issue through a browser.
The following exploit code is available:
Solution / Fix
zKup Authentication Bypass Vulnerability
Solution:
The vendor released zKup 2.04 to address this issue. Please see the references for more information.
Solution:
The vendor released zKup 2.04 to address this issue. Please see the references for more information.
References
zKup Authentication Bypass Vulnerability
References:
References:
- zKup CMS v2.0 <= v2.3 0-day exploit (upload) (milw0rm)
- zKup v2 Homepage (zKup)