CVE Vulnerabilities

CVE-2010-1191

Improper Authentication

Published: Mar 31, 2010 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:P
RedHat/V2
6.4 MODERATE
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu

Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable administrator authentication via a direct request to stream.php in an acl_enable_acl action to the admin module.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Sahana Sahanafoundation 0.6.2.2 (including) 0.6.2.2 (including)

Potential Mitigations

References