|
|

CVE Reference: CVE-2008-7050 |
|
| NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE. | |
|
Original Page at CVE MITRE: CVE-2008-7050 |
|
|
Description: The password_check function in auth/auth_phpbb3.php in WoW Raid Manager 3.5.1 before Patch 1, when using PHPBB3 authentication, (1) does not invoke the CheckPassword function with the required arguments, which always triggers an authentication failure, and (2) returns true instead of false when an authentication failure occurs, which allows remote attackers to bypass authentication and gain privileges with an arbitrary password. |
|
|
CVE Status: Candidate |
|
|
References: SAID Secunia Advisory: SA32653 OSVDB 49704 MISC http://github.com/Illydth/wowraidmanager/commit/7dd6367ae85003dd5d715431b6ab695f2c2f200a CONFIRM http://www.wowraidmanager.net/e107_plugins/forum/forum_viewtopic.php?2153 http://www.wowraidmanager.net/e107_plugins/forum/forum_viewtopic.php?2167 |
|
| Return to the previous page. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |