MyGuestbook user_modif.php Authentication Failure Vulnerability
BID:6911
Info
MyGuestbook user_modif.php Authentication Failure Vulnerability
| Bugtraq ID: | 6911 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2003 12:00AM |
| Updated: | Feb 21 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to: "Frog Man" <[email protected]>. |
| Vulnerable: |
tefonline.net Myguestbook 3.0 |
| Not Vulnerable: | |
Discussion
MyGuestbook user_modif.php Authentication Failure Vulnerability
It has been reported that in some cases MyGuestbook fails to validate the authenticity of a remote user before taking privileged actions.
The attacker may attain the ability to modify data contained in a guest book without the software sufficiently checking whether the operation is permitted for the user.
This vulnerability has been reported for MyGuestbook version 3.0, previous versions may also be affected.
It has been reported that in some cases MyGuestbook fails to validate the authenticity of a remote user before taking privileged actions.
The attacker may attain the ability to modify data contained in a guest book without the software sufficiently checking whether the operation is permitted for the user.
This vulnerability has been reported for MyGuestbook version 3.0, previous versions may also be affected.
Exploit / POC
MyGuestbook user_modif.php Authentication Failure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
MyGuestbook user_modif.php Authentication Failure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.