Invision Power Board OpenID Authentication Bypass Vulnerability
BID:42415
Info
Invision Power Board OpenID Authentication Bypass Vulnerability
| Bugtraq ID: | 42415 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2009 12:00AM |
| Updated: | Jan 05 2011 08:52PM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
Invision Power Services Invision Power Board 3.0.2 |
| Not Vulnerable: |
Invision Power Services Invision Power Board 3.0.3 |
Discussion
Invision Power Board OpenID Authentication Bypass Vulnerability
OpenID for Invision Power Board is prone to an authentication-bypass vulnerability.
Attackers may exploit these issues to gain unauthorized access to user accounts or to bypass intended security restrictions. Other attacks may also be possible.
Invision Power Board 3.0.2 prior to August 26th, 2009 is vulnerable; other versions may be affected.
http://drupal.org/node/207891
OpenID for Invision Power Board is prone to an authentication-bypass vulnerability.
Attackers may exploit these issues to gain unauthorized access to user accounts or to bypass intended security restrictions. Other attacks may also be possible.
Invision Power Board 3.0.2 prior to August 26th, 2009 is vulnerable; other versions may be affected.
http://drupal.org/node/207891
Exploit / POC
Invision Power Board OpenID Authentication Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Invision Power Board OpenID Authentication Bypass Vulnerability
Solution:
Updates are available; please see the references for details.
Solution:
Updates are available; please see the references for details.
References
Invision Power Board OpenID Authentication Bypass Vulnerability
References:
References:
- Invision Power Services - Homepage (Invision Power Services)
- OpenID Security Update for IP.Board 3.0.2 (Invision Power Services)