TaskDriver Cookie Authentication Bypass Vulnerability
BID:33030
Info
TaskDriver Cookie Authentication Bypass Vulnerability
| Bugtraq ID: | 33030 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2008 12:00AM |
| Updated: | Jan 02 2009 04:21PM |
| Credit: | cOndemned |
| Vulnerable: |
TaskDriver TaskDriver 1.3 TaskDriver TaskDriver 1.2 |
| Not Vulnerable: | |
Discussion
TaskDriver Cookie Authentication Bypass Vulnerability
TaskDriver is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
Attackers can exploit this vulnerability to gain unauthorized access to the affected application, which may aid in further attacks.
Versions up to and including TaskDriver 1.3 are vulnerable.
TaskDriver is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
Attackers can exploit this vulnerability to gain unauthorized access to the affected application, which may aid in further attacks.
Versions up to and including TaskDriver 1.3 are vulnerable.
Exploit / POC
TaskDriver Cookie Authentication Bypass Vulnerability
Attackers can exploit this issue via a browser.
The following exploit is available:
Attackers can exploit this issue via a browser.
The following exploit is available:
Solution / Fix
TaskDriver Cookie Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].