PT-2009-2519 · Blizzard+1 · Wow Raid Manager+1

Publicado

2009-08-24

·

Atualizado

2009-08-24

·

CVE-2008-7050

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WoW Raid Manager version 3.5.1
Description The issue concerns the password check function in the auth/auth phpbb3.php file when using PHPBB3 authentication. It has two main problems: (1) it does not correctly invoke the CheckPassword function with the necessary arguments, leading to authentication failures, and (2) it returns true instead of false when an authentication failure occurs. This allows remote attackers to bypass authentication with any password, potentially gaining privileges.
Recommendations For WoW Raid Manager version 3.5.1, apply Patch 1 to fix the authentication bypass issue in the password check function.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-7050

Produtos afetados

Phpbb3
Wow Raid Manager