Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-7050
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-7050

Description:
The password_check function in auth/auth_phpbb3.php in WoW Raid Manager 3.5.1 before Patch 1, when using PHPBB3 authentication, (1) does not invoke the CheckPassword function with the required arguments, which always triggers an authentication failure, and (2) returns true instead of false when an authentication failure occurs, which allows remote attackers to bypass authentication and gain privileges with an arbitrary password.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA32653

OSVDB
  49704

MISC
  http://github.com/Illydth/wowraidmanager/commit/7dd6367ae85003dd5d715431b6ab695f2c2f200a

CONFIRM
  http://www.wowraidmanager.net/e107_plugins/forum/forum_viewtopic.php?2153
  http://www.wowraidmanager.net/e107_plugins/forum/forum_viewtopic.php?2167


Return to the previous page.