7.5

CVE-2008-7050

Exploit
The password_check function in auth/auth_phpbb3.php in WoW Raid Manager 3.5.1 before Patch 1, when using PHPBB3 authentication, (1) does not invoke the CheckPassword function with the required arguments, which always triggers an authentication failure, and (2) returns true instead of false when an authentication failure occurs, which allows remote attackers to bypass authentication and gain privileges with an arbitrary password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WowraidmanagerWowraidmanager Version <= 3.5.1
WowraidmanagerWowraidmanager Version3.1.0
WowraidmanagerWowraidmanager Version3.1.1
WowraidmanagerWowraidmanager Version3.1.2
WowraidmanagerWowraidmanager Version3.2.0
WowraidmanagerWowraidmanager Version3.2.1
WowraidmanagerWowraidmanager Version3.5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.89% 0.768
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://github.com/Illydth/wowraidmanager/commit/7dd6367ae85003dd5d715431b6ab695f2c2f200a
Exploit
http://secunia.com/advisories/32653
Vendor Advisory
http://www.osvdb.org/49704
http://www.vupen.com/english/advisories/2008/3109
Patch
Vendor Advisory
http://www.wowraidmanager.net/e107_plugins/forum/forum_viewtopic.php?2153
Vendor Advisory
http://www.wowraidmanager.net/e107_plugins/forum/forum_viewtopic.php?2167
Patch
Vendor Advisory