CVE Vulnerabilities

CVE-2006-4427

Published: Aug 29, 2006 | Modified: Oct 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (1) adminloggedin, (2) loggedin, and (3) level parameters to 1.

Affected Software

Name Vendor Start Version End Version
Efiction Efiction 1.0 (including) 1.0 (including)
Efiction Efiction 1.1 (including) 1.1 (including)
Efiction Efiction 2.0 (including) 2.0 (including)
Efiction Efiction 2.0.6 (including) 2.0.6 (including)

References