CVE Vulnerabilities

CVE-2011-5253

Improper Authentication

Published: Jan 12, 2013 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Dl Download Ticket Service 0.3 through 0.9 allows remote attackers to login as an arbitrary user by supplying an authorization header.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Dl Thegr 0.3 (including) 0.3 (including)
Dl Thegr 0.4 (including) 0.4 (including)
Dl Thegr 0.5 (including) 0.5 (including)
Dl Thegr 0.6 (including) 0.6 (including)
Dl Thegr 0.7 (including) 0.7 (including)
Dl Thegr 0.8 (including) 0.8 (including)
Dl Thegr 0.9 (including) 0.9 (including)

Potential Mitigations

References