simplePHPWeb 'file.php' Authentication Bypass Vulnerability
BID:42557
Info
simplePHPWeb 'file.php' Authentication Bypass Vulnerability
| Bugtraq ID: | 42557 |
| Class: | Design Error |
| CVE: |
CVE-2009-3158 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 03 2009 12:00AM |
| Updated: | Dec 07 2011 08:57PM |
| Credit: | SirGod |
| Vulnerable: |
Carsten Wulff simplePHPWeb 0.2 |
| Not Vulnerable: | |
Discussion
simplePHPWeb 'file.php' Authentication Bypass Vulnerability
simplePHPWeb is prone to an authentication-bypass vulnerability because it fails to restrict unauthenticated access.
Successful exploits may allow attackers to bypass security restrictions and gain unauthorized access; other attacks may also be possible.
simplePHPWeb 0.2 is vulnerable; other versions may also be affected.
simplePHPWeb is prone to an authentication-bypass vulnerability because it fails to restrict unauthenticated access.
Successful exploits may allow attackers to bypass security restrictions and gain unauthorized access; other attacks may also be possible.
simplePHPWeb 0.2 is vulnerable; other versions may also be affected.
Exploit / POC
simplePHPWeb 'file.php' Authentication Bypass Vulnerability
An attacker can carry out this attack using readily available network utilities.
An attacker can carry out this attack using readily available network utilities.
Solution / Fix
simplePHPWeb 'file.php' Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
simplePHPWeb 'file.php' Authentication Bypass Vulnerability
References:
References:
- simplePHPWeb Project Page (SourceForge)