eXtplorer 'ext_find_user()' Function Authentication Bypass Vulnerability
BID:57058
CVE-2012-6710 |Info
eXtplorer 'ext_find_user()' Function Authentication Bypass Vulnerability
| Bugtraq ID: | 57058 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 27 2012 12:00AM |
| Updated: | Jan 10 2013 05:30PM |
| Credit: | Brendan Coles of itsecuritysolutions.org |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
eXtplorer 'ext_find_user()' Function Authentication Bypass Vulnerability
eXtplorer is prone to an authentication-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized access.
eXtplorer 2.1.2, 2.1.1, and 2.1.0 are vulnerable.
eXtplorer is prone to an authentication-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized access.
eXtplorer 2.1.2, 2.1.1, and 2.1.0 are vulnerable.
Exploit / POC
eXtplorer 'ext_find_user()' Function Authentication Bypass Vulnerability
Attackers can exploit this issue with a web browser.
The following exploit is available:
Attackers can exploit this issue with a web browser.
The following exploit is available:
Solution / Fix
eXtplorer 'ext_find_user()' Function Authentication Bypass Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
eXtplorer 'ext_find_user()' Function Authentication Bypass Vulnerability
References:
References: