Vulnerability CVE-2008-7050


Published: 2009-08-24   Modified: 2012-02-12

Description:
The password_check function in auth/auth_phpbb3.php in WoW Raid Manager 3.5.1 before Patch 1, when using PHPBB3 authentication, (1) does not invoke the CheckPassword function with the required arguments, which always triggers an authentication failure, and (2) returns true instead of false when an authentication failure occurs, which allows remote attackers to bypass authentication and gain privileges with an arbitrary password.

Type:

CWE-255

(Credentials Management)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Wowraidmanager -> Wowraidmanager 

 References:
http://www.wowraidmanager.net/e107_plugins/forum/forum_viewtopic.php?2167
http://www.vupen.com/english/advisories/2008/3109
http://www.wowraidmanager.net/e107_plugins/forum/forum_viewtopic.php?2153
http://www.osvdb.org/49704
http://secunia.com/advisories/32653
http://github.com/Illydth/wowraidmanager/commit/7dd6367ae85003dd5d715431b6ab695f2c2f200a

Copyright 2024, cxsecurity.com

 

Back to Top