openInvoice Security Bypass Vulnerabilities
BID:28854
Info
openInvoice Security Bypass Vulnerabilities
| Bugtraq ID: | 28854 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-6524 CVE-2008-6523 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 18 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | t0pP8uZz |
| Vulnerable: |
openInvoice openInvoice 0.90 Beta |
| Not Vulnerable: | |
Discussion
openInvoice Security Bypass Vulnerabilities
openInvoice is prone to multiple security-bypass vulnerabilities because it fails to properly validate user credentials before performing certain actions.
Exploiting this issue may allow an attacker to bypass certain security restrictions and reset the passwords of arbitrary users of the vulnerable application. This may compromise the application and aid in further attacks.
This issue affects openInvoice 0.90 Beta; other versions may also be vulnerable.
openInvoice is prone to multiple security-bypass vulnerabilities because it fails to properly validate user credentials before performing certain actions.
Exploiting this issue may allow an attacker to bypass certain security restrictions and reset the passwords of arbitrary users of the vulnerable application. This may compromise the application and aid in further attacks.
This issue affects openInvoice 0.90 Beta; other versions may also be vulnerable.
Exploit / POC
openInvoice Security Bypass Vulnerabilities
The following proof-of-concept exploit is available:
The following proof-of-concept exploit is available:
Solution / Fix
openInvoice Security Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].