eL DAPo Authentication Information Disclosure Weakness
BID:6735
Info
eL DAPo Authentication Information Disclosure Weakness
| Bugtraq ID: | 6735 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2003 12:00AM |
| Updated: | Jan 30 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Secunia. |
| Vulnerable: |
eL DAPo eL DAPo 1.13 eL DAPo eL DAPo 1.12.1 eL DAPo eL DAPo 1.12 eL DAPo eL DAPo 1.11 eL DAPo eL DAPo 1.10 |
| Not Vulnerable: |
eL DAPo eL DAPo 1.14 |
Discussion
eL DAPo Authentication Information Disclosure Weakness
An information disclosure weakness has been reported for eL DAPo. The issue exists in the login.php script used by eL DAPo. Specifically, when sending authentication information to query LDAP servers, any information submitted may be visible in URI parameters.
It is possible to exploit this weakness to obtain authentication credentials of unsuspecting users.
An information disclosure weakness has been reported for eL DAPo. The issue exists in the login.php script used by eL DAPo. Specifically, when sending authentication information to query LDAP servers, any information submitted may be visible in URI parameters.
It is possible to exploit this weakness to obtain authentication credentials of unsuspecting users.
Exploit / POC
eL DAPo Authentication Information Disclosure Weakness
There is no exploit required.
There is no exploit required.