Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Authentication Bypas in BASE version 1.2.4 and prior Jun 23 2009 08:31PM
timmedin gmail com
Versions prior to 1.2.4 are affected. The issue was fixed in version 1.2.5.

The authentication process checks the cookies to see if the user has a given role. The user and role defined in the cookie is not validated during this process. An attacker can add a cookie (shown below) in order to bypass ...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus