Support Incident Tracker Blank Password Authentication Bypass Vulnerability
BID:37949
Info
Support Incident Tracker Blank Password Authentication Bypass Vulnerability
| Bugtraq ID: | 37949 |
| Class: | Design Error |
| CVE: |
CVE-2010-1596 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 23 2010 12:00AM |
| Updated: | Apr 13 2015 09:03PM |
| Credit: | The vendor |
| Vulnerable: |
Support Incident Tracker SiT! 3.50 Support Incident Tracker SiT! 3.30 Support Incident Tracker SiT! 3.24 |
| Not Vulnerable: |
Support Incident Tracker SiT! 3.51 |
Discussion
Support Incident Tracker Blank Password Authentication Bypass Vulnerability
Support Incident Tracker (SiT!) is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
Versions prior to Support Incident Tracker (SiT!) 3.51 are vulnerable.
Support Incident Tracker (SiT!) is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the affected application.
Versions prior to Support Incident Tracker (SiT!) 3.51 are vulnerable.
Exploit / POC
Support Incident Tracker Blank Password Authentication Bypass Vulnerability
An attacker can exploit this issue using client applications.
An attacker can exploit this issue using client applications.
Solution / Fix
Support Incident Tracker Blank Password Authentication Bypass Vulnerability
Solution:
The vendor has released an update. Please see the references for more information.
Solution:
The vendor has released an update. Please see the references for more information.
References
Support Incident Tracker Blank Password Authentication Bypass Vulnerability
References:
References:
- Support Incident Tracker Homepage (Support Incident Tracker)
- ReleaseNotes351 (Support Incident Tracker)