CVE Vulnerabilities

CVE-2004-2254

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.

Affected Software

NameVendorStart VersionEnd Version
SurgeldapNetwin1.0a (including)1.0a (including)
SurgeldapNetwin1.0b (including)1.0b (including)
SurgeldapNetwin1.0d (including)1.0d (including)
SurgeldapNetwin1.0e (including)1.0e (including)
SurgeldapNetwin1.0f (including)1.0f (including)
SurgeldapNetwin1.0g (including)1.0g (including)

References