RETIRED: Achievo 'dispatch.php' Multiple Security Bypass Vulnerabilities
BID:43572
Info
RETIRED: Achievo 'dispatch.php' Multiple Security Bypass Vulnerabilities
| Bugtraq ID: | 43572 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2010 12:00AM |
| Updated: | Sep 29 2010 04:10PM |
| Credit: | Pablo G. Milano |
| Vulnerable: |
Achievo Achievo 1.4.3 |
| Not Vulnerable: |
Achievo Achievo 1.4.5 |
Discussion
RETIRED: Achievo 'dispatch.php' Multiple Security Bypass Vulnerabilities
Achievo is prone to multiple security-bypass vulnerabilities that may allow attackers to perform actions without proper authorization.
Attackers can exploit these issues to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Achievo 1.4.3 is vulnerable; other versions may also be affected.
RETIRED: This BID is retired because it is a duplicate of BID 43544 (Achievo Time Registration Module 'dispatch.php' Security Bypass Vulnerability).
Achievo is prone to multiple security-bypass vulnerabilities that may allow attackers to perform actions without proper authorization.
Attackers can exploit these issues to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Achievo 1.4.3 is vulnerable; other versions may also be affected.
RETIRED: This BID is retired because it is a duplicate of BID 43544 (Achievo Time Registration Module 'dispatch.php' Security Bypass Vulnerability).
Exploit / POC
RETIRED: Achievo 'dispatch.php' Multiple Security Bypass Vulnerabilities
Attackers can exploit this issue through a browser.
The following example URI is available:
http://www.example.com/dispatch.php?atknodetype=timereg.hours&atkaction=delete&atkselector=hoursbase.id='XXXX'
XXXX is the ID of the activity to be deleted.
Attackers can exploit this issue through a browser.
The following example URI is available:
http://www.example.com/dispatch.php?atknodetype=timereg.hours&atkaction=delete&atkselector=hoursbase.id='XXXX'
XXXX is the ID of the activity to be deleted.
Solution / Fix
RETIRED: Achievo 'dispatch.php' Multiple Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
RETIRED: Achievo 'dispatch.php' Multiple Security Bypass Vulnerabilities
References:
References:
- Achievo 1.4.5 Release Notes (Achievo)
- Achievo Homepage (Achievo)