|
|||||||||||
|
Ragnarok Online Control Panel Authentication Bypass Vulnerability [new method]
From: <dp14(at)hotmail.com>
Date: Fri Aug 31 2007 - 08:05:51 EDT
The vulnerability is caused due to an error in the authentication process when checking page access. This can be exploited to bypass the authentication process via a specially crafted URL with an appended non-restricted page. The /.../ reffers to directory crawling
Example:
Successful exploitation requires that files are served from an Apache HTTP server. The vulnerability has been reported in version 4.3.4a. Other versions may also be affected. SOLUTION:
PROVIDED AND/OR DISCOVERED BY:
This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:14:05 EDT |
||||||||||
|
|||||||||||