CVE Vulnerabilities

CVE-2005-4006

Improper Authentication

Published: Dec 05, 2005 | Modified: Oct 22, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (1) insert_file.php, (2) insert_image.php, (3) insert_link.php, (4) insert_qcfile.php, and (5) edit.php.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Sapid_cms Redgraphic * 1.2.3.02 (including)
Sapid_cms Redgraphic 1.2.3 (including) 1.2.3 (including)
Sapid_cms Redgraphic 1.2.3-rc2 (including) 1.2.3-rc2 (including)
Sapid_cms Redgraphic 1.2.3-rc3 (including) 1.2.3-rc3 (including)
Sapid_cms Redgraphic 1.2.3-rc5 (including) 1.2.3-rc5 (including)
Sapid_cms Redgraphic 1.2.3-stable (including) 1.2.3-stable (including)

Potential Mitigations

References