RSS   Vulnerabilities for 'Ragnarok online control panel'   RSS

2007-09-05
 
CVE-2007-4723

CWE-287
 

 
Directory traversal vulnerability in Ragnarok Online Control Panel 4.3.4a, when the Apache HTTP Server is used, allows remote attackers to bypass authentication via directory traversal sequences in a URI that ends with the name of a publicly available page, as demonstrated by a "/...../" sequence and an account_manage.php/login.php final component for reaching the protected account_manage.php page.

 
2005-12-31
 
CVE-2005-4861

 

 
functions.php in Ragnarok Online Control Panel (ROCP) 4.3.4a allows remote attackers to bypass authentication by requesting account_manage.php with a trailing "/login.php" PHP_SELF value, which is not properly handled by the CHECK_AUTH function.

 


Copyright 2024, cxsecurity.com

 

Back to Top