PHPRank MySQL Error Unauthorized Access Vulnerability
BID:5948
Info
PHPRank MySQL Error Unauthorized Access Vulnerability
| Bugtraq ID: | 5948 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 10 2002 12:00AM |
| Updated: | Oct 10 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Jedi/Sector One <[email protected]>. |
| Vulnerable: |
phpRank phpRank 1.8 |
| Not Vulnerable: | |
Discussion
PHPRank MySQL Error Unauthorized Access Vulnerability
phpRank does not provide sufficient error checking with regards to functions which access the underlying MySQL database. As a result, when the database is inaccessible or temporarily unavailable it is possible for remote attackers to authenticate as any user to phpRank using a null password.
This problem occurs because the vulnerable script still attempts to authenticate the user even though authentication data cannot be fetched from the database.
phpRank does not provide sufficient error checking with regards to functions which access the underlying MySQL database. As a result, when the database is inaccessible or temporarily unavailable it is possible for remote attackers to authenticate as any user to phpRank using a null password.
This problem occurs because the vulnerable script still attempts to authenticate the user even though authentication data cannot be fetched from the database.
Exploit / POC
PHPRank MySQL Error Unauthorized Access Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
PHPRank MySQL Error Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.