phpScheduleIt 'useLogonName' Security Bypass Vulnerability
BID:30300
Info
phpScheduleIt 'useLogonName' Security Bypass Vulnerability
| Bugtraq ID: | 30300 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-3268 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2008 12:00AM |
| Updated: | May 07 2015 05:27PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
phpScheduleIt phpScheduleIt 1.2.9 phpScheduleIt phpScheduleIt 1.2.8 phpScheduleIt phpScheduleIt 1.2.7 phpScheduleIt phpScheduleIt 1.2.6 phpScheduleIt phpScheduleIt 1.2.5 phpScheduleIt phpScheduleIt 1.2.4 phpScheduleIt phpScheduleIt 1.2.3 phpScheduleIt phpScheduleIt 1.2.2 phpScheduleIt phpScheduleIt 1.2.1 phpScheduleIt phpScheduleIt 1.2 |
| Not Vulnerable: |
phpScheduleIt phpScheduleIt 1.2.10 |
Discussion
phpScheduleIt 'useLogonName' Security Bypass Vulnerability
phpScheduleIt is prone to a vulnerability that gives an attacker unauthorized access to administration areas of the application because the software fails to properly restrict access in an unspecified script.
An attacker can leverage this vulnerability to gain administrative access to the application.
Versions up to and including phpScheduleIt 1.2.9 are vulnerable.
phpScheduleIt is prone to a vulnerability that gives an attacker unauthorized access to administration areas of the application because the software fails to properly restrict access in an unspecified script.
An attacker can leverage this vulnerability to gain administrative access to the application.
Versions up to and including phpScheduleIt 1.2.9 are vulnerable.
Exploit / POC
phpScheduleIt 'useLogonName' Security Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
phpScheduleIt 'useLogonName' Security Bypass Vulnerability
Solution:
The vendor has released a fix. Please see the references for more information.
Solution:
The vendor has released a fix. Please see the references for more information.
References
phpScheduleIt 'useLogonName' Security Bypass Vulnerability
References:
References:
- phpScheduleIt Homepage (phpScheduleIt)
- phpScheduleIt Project Page (phpScheduleIt)