WOW Raid Manager 'auth/auth_phpbb3.php' Security Bypass Vulnerability
BID:32250
Info
WOW Raid Manager 'auth/auth_phpbb3.php' Security Bypass Vulnerability
| Bugtraq ID: | 32250 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-7050 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2008 12:00AM |
| Updated: | Sep 15 2009 08:11PM |
| Credit: | WOW Raid Manager |
| Vulnerable: |
WOW Raid Manager WOW Raid Manager 3.5.1 WOW Raid Manager WOW Raid Manager 3.5.1 WOW Raid Manager WOW Raid Manager 3.5 |
| Not Vulnerable: |
WOW Raid Manager WOW Raid Manager 3.6 |
Discussion
WOW Raid Manager 'auth/auth_phpbb3.php' Security Bypass Vulnerability
WOW Raid Manager is prone to a security-bypass vulnerability.
Attackers may exploit the issue to bypass certain security restrictions and gain unauthorized access to the application.
Versions prior to WOW Raid Manager 3.6.0 are vulnerable.
WOW Raid Manager is prone to a security-bypass vulnerability.
Attackers may exploit the issue to bypass certain security restrictions and gain unauthorized access to the application.
Versions prior to WOW Raid Manager 3.6.0 are vulnerable.
Exploit / POC
WOW Raid Manager 'auth/auth_phpbb3.php' Security Bypass Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
WOW Raid Manager 'auth/auth_phpbb3.php' Security Bypass Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
WOW Raid Manager 'auth/auth_phpbb3.php' Security Bypass Vulnerability
References:
References:
- Bug Fix: Fixes problem with phpBB3 bridge allowing login with ANY password. (WOW Raid Manager)
- WOW Raid Manager Homepage (WOW Raid Manager)
- WOW Raid Manager Support Forums (WOW Raid Manager)