Elite News Administrative Authentication Bypass Vulnerability
BID:8216
Info
Elite News Administrative Authentication Bypass Vulnerability
| Bugtraq ID: | 8216 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2003 12:00AM |
| Updated: | Jul 16 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Jim Pangalos <[email protected]>. |
| Vulnerable: |
Firestorm Corporation Elite News 1.0.3 Beta Firestorm Corporation Elite News 1.0.3 Firestorm Corporation Elite News 1.0 |
| Not Vulnerable: | |
Discussion
Elite News Administrative Authentication Bypass Vulnerability
Elite News has been reported prone to an administrative authentication bypass vulnerability.
The issue reportedly presents itself due to a combination of factors; a remote attacker may extract the administrator username by viewing an Elite News script. This username may then be applied in the login page, without requiring a password to authenticate. The attacker may then access other Elite News scripts directly and take actions as the Elite News administrator.
Elite News has been reported prone to an administrative authentication bypass vulnerability.
The issue reportedly presents itself due to a combination of factors; a remote attacker may extract the administrator username by viewing an Elite News script. This username may then be applied in the login page, without requiring a password to authenticate. The attacker may then access other Elite News scripts directly and take actions as the Elite News administrator.
Exploit / POC
Elite News Administrative Authentication Bypass Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Elite News Administrative Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Elite News Administrative Authentication Bypass Vulnerability
References:
References:
- Elite News Homepage (Firestorm Corporation)
- ZH2003-11SA (security advisory): Elite News Ver. 1.0.0.0-1.0.0.3 Beta (Jim Pangalos
)