CVE Vulnerabilities

CVE-2007-3193

Published: Jun 12, 2007 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.

Affected Software

Name Vendor Start Version End Version
Phpwiki Phpwiki * 1.3.13 (including)
Phpwiki Ubuntu dapper *
Phpwiki Ubuntu devel *
Phpwiki Ubuntu edgy *
Phpwiki Ubuntu feisty *
Phpwiki Ubuntu gutsy *
Phpwiki Ubuntu hardy *
Phpwiki Ubuntu intrepid *
Phpwiki Ubuntu jaunty *
Phpwiki Ubuntu karmic *

References