Owl Intranet Engine Authentication Bypass Vulnerability
BID:7595
Info
Owl Intranet Engine Authentication Bypass Vulnerability
| Bugtraq ID: | 7595 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2003 12:00AM |
| Updated: | May 14 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to cdowns <[email protected]>. |
| Vulnerable: |
Owl Owl Intranet Engine 0.7 |
| Not Vulnerable: | |
Discussion
Owl Intranet Engine Authentication Bypass Vulnerability
Owl has been reported prone to an authentication bypass vulnerability.
The issue presents itself due to a lack of sufficient sanitization when checking the validity of usernames and passwords supplied to 'browse.php'.
An attacker may exploit this condition to bypass the Owl authentication system.
Owl has been reported prone to an authentication bypass vulnerability.
The issue presents itself due to a lack of sufficient sanitization when checking the validity of usernames and passwords supplied to 'browse.php'.
An attacker may exploit this condition to bypass the Owl authentication system.
Exploit / POC
Owl Intranet Engine Authentication Bypass Vulnerability
The following proof of concept has been supplied:
http://www.example.com/intranet/browse.php?loginname=whocares&parent=1&expand=1&order=creatorid&sortposted=ASC
The following proof of concept has been supplied:
http://www.example.com/intranet/browse.php?loginname=whocares&parent=1&expand=1&order=creatorid&sortposted=ASC
Solution / Fix
Owl Intranet Engine Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Owl Intranet Engine Authentication Bypass Vulnerability
References:
References:
- Owl Intranet Engine - bypass admin (cdowns
) - Owl Intranet Engine Homepage (Owl)