JAKCMS PRO 'session.php' Authentication Bypass Vulnerability
BID:49737
Info
JAKCMS PRO 'session.php' Authentication Bypass Vulnerability
| Bugtraq ID: | 49737 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2011 12:00AM |
| Updated: | Sep 22 2011 12:00AM |
| Credit: | EgiX |
| Vulnerable: |
JAKCMS JAKCMS PRO 2.2.5 |
| Not Vulnerable: |
JAKCMS JAKCMS PRO 2.2.6 |
Discussion
JAKCMS PRO 'session.php' Authentication Bypass Vulnerability
JAKCMS PRO is prone to an authentication-bypass vulnerability.
Attackers can exploit this issue to gain unauthorized access to the affected application and perform arbitrary actions.
JAKCMS PRO 2.2.5 and prior versions are vulnerable.
JAKCMS PRO is prone to an authentication-bypass vulnerability.
Attackers can exploit this issue to gain unauthorized access to the affected application and perform arbitrary actions.
JAKCMS PRO 2.2.5 and prior versions are vulnerable.
Exploit / POC
JAKCMS PRO 'session.php' Authentication Bypass Vulnerability
Attackers can exploit this issue via a browser.
The following exploit is available:
Attackers can exploit this issue via a browser.
The following exploit is available:
Solution / Fix
JAKCMS PRO 'session.php' Authentication Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
JAKCMS PRO 'session.php' Authentication Bypass Vulnerability
References:
References:
- JAKCMS PRO Homepage (JAKCMS)
- Security Flaw (Image/Filemanager) (EgiX)