Ananta CMS 'change.php' Authentication Bypass Vulnerability
BID:29752
Info
Ananta CMS 'change.php' Authentication Bypass Vulnerability
| Bugtraq ID: | 29752 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-6665 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | CWH Underground |
| Vulnerable: |
Ananta Ananta CMS 1.0 b5 |
| Not Vulnerable: | |
Discussion
Ananta CMS 'change.php' Authentication Bypass Vulnerability
Ananta CMS is prone to an authentication-bypass vulnerability because it fails to perform authentication checks on certain portions of the application.
An attacker can exploit this issue to gain unauthorized access to the affected application. This may lead to further attacks.
Ananta CMS 1.0b5 is vulnerable; other versions may also be affected.
Ananta CMS is prone to an authentication-bypass vulnerability because it fails to perform authentication checks on certain portions of the application.
An attacker can exploit this issue to gain unauthorized access to the affected application. This may lead to further attacks.
Ananta CMS 1.0b5 is vulnerable; other versions may also be affected.
Exploit / POC
Ananta CMS 'change.php' Authentication Bypass Vulnerability
An attacker can use a browser to exploit this issue.
The following HTTP POST request is available:
An attacker can use a browser to exploit this issue.
The following HTTP POST request is available:
Solution / Fix
Ananta CMS 'change.php' Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ananta CMS 'change.php' Authentication Bypass Vulnerability
References:
References:
- Ananta CMS Homepage (Ananta)