OSVDB ID: 15348

Title: Access_user Class Undocumented Backdoor Password

Info

Disclosure

Apr 07, 2005

Discovery

Unknown

Dates

Exploit

Apr 07, 2005

Solution

Unknown

Description

The Access_user class allows access to any account when a valid account name is entered with the word "new" as the password. This allows attackers to trivially access the program or system.

Classification

Location: Remote / Network Access
Attack Type: Authentication Management
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Public
Disclosure: OSVDB Verified, Vendor Verified

Solution

Upgrade to version 1.75 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Olaf Lederer

Access_user Class

1.7.4

References

Credit

  • Mike -


Direct URL: http://osvdb.org/15348