Информационная безопасность
[RU] switch to
English Version



Дополнительная информация

  Ежедневная сводка ошибок в Web-приложениях (PHP, ASP, JSP, CGI, Perl )

  PR07-23: Non-persistent Cross-site Scripting (XSS) on Absolute Poll Manager XE admin page

  Vulnerability in Joomla!

From:dp14_(at)_hotmail.com <dp14_(at)_hotmail.com>
Date:31 августа 2007 г.
Subject:Ragnarok Online Control Panel Authentication Bypass Vulnerability [new method]

VaLiuS has reported a vulnerability in Ragnarok Online Control Panel,
which can be exploited by malicious people to bypass certain security
restrictions.

The vulnerability is caused due to an error in the authentication
process when checking page access. This can be exploited to bypass
the authentication process via a specially crafted URL with an
appended non-restricted page.

The /.../ reffers to directory crawling

Example:
http://www.example.com/CP/...../account_manage.php/login.php

Successful exploitation requires that files are served from an Apache
HTTP server.

The vulnerability has been reported in version 4.3.4a. Other versions
may also be affected.

SOLUTION:
Edit the source code to ensure that the authentication process is
properly performed.

PROVIDED AND/OR DISCOVERED BY:
Calypso Steweren

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород
 



Rating@Mail.ru