Vulnerability CVE-2005-2963


Published: 2005-10-13   Modified: 2012-02-12

Description:
The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Mod auth shadow -> Mod auth shadow 

 References:
http://xforce.iss.net/xforce/xfdb/22520
http://www.debian.org/security/2005/dsa-844
http://secunia.com/advisories/17060/
http://www.securityfocus.com/bid/15224
http://www.osvdb.org/19863
http://secunia.com/advisories/17348
http://secunia.com/advisories/17067
http://frontal1.mandriva.com/security/advisories?name=MDKSA-2005:200
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=323789

Copyright 2024, cxsecurity.com

 

Back to Top