Aldap Contact Manager Authentication Bypass Vulnerability
BID:6310
Info
Aldap Contact Manager Authentication Bypass Vulnerability
| Bugtraq ID: | 6310 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2002 12:00AM |
| Updated: | Dec 03 2002 12:00AM |
| Credit: | This vulnerability was first detailed in the product's changelog. |
| Vulnerable: |
Aldap Aldap 0.9 |
| Not Vulnerable: |
Aldap Aldap 0.9 -2 Aldap Aldap 0.9 -1 |
Discussion
Aldap Contact Manager Authentication Bypass Vulnerability
An authentication bypassing vulnerability has been reported for Aldap. Reportedly, it may be possible for attackers to login to the Aldap contact manager with 'Manager' privileges regardless of the supplied password.
An authentication bypassing vulnerability has been reported for Aldap. Reportedly, it may be possible for attackers to login to the Aldap contact manager with 'Manager' privileges regardless of the supplied password.
Exploit / POC
Aldap Contact Manager Authentication Bypass Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Aldap Contact Manager Authentication Bypass Vulnerability
Solution:
The following fixes are available:
Aldap Aldap 0.9
Solution:
The following fixes are available:
Aldap Aldap 0.9
-
Aldap aldap-0.09-2.tar.gz
http://alcastle.com/redirect.php?url=public/aldap/0_09/aldap-0.09-2.ta r.gz