OSVDB ID: 22344

Title: ACal login.php ACalAuthenticate Cookie Manipulation Authentication Bypass

Info

Disclosure

Jan 12, 2006

Discovery

Unknown

Dates

Exploit

Jan 12, 2006

Solution

Unknown

Description

ACal contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when an 'ACalAuthenticate' cookie is sent to the 'login.php' script with the value 'inside'. This flaw may lead to an attacker gaining unauthorised access, leading to a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Authentication Management
Impact: Loss of Integrity
Exploit: Exploit Public
OSVDB: Web Related

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

ACal Calendar Project

ACal

2.2.5

References

Credit

  • Aliaksandr Hartsuyeu - alexevuln.com - eVuln


Direct URL: http://osvdb.org/22344