Vulnerabilities > CVE-2004-2155
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN nessus
Summary
Online-bookmarks before 0.4.6 allows remote attackers to bypass its authentication mechanism via a direct request to (1) config/*, (2) bookmarks.php, (3) footer.php, (4) main.php, (5) tree.php, or (6) functions.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200901-08.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200901-08 (Online-Bookmarks: Multiple vulnerabilities) The following vulnerabilities were reported: Authentication bypass when directly requesting certain pages (CVE-2004-2155). Insufficient input validation in the login function in auth.inc (CVE-2006-6358). Unspecified cross-site scripting vulnerability (CVE-2006-6359). Impact : A remote attacker could exploit these vulnerabilities to bypass authentication mechanisms, execute arbitrary SQL statements or inject arbitrary web scripts. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 35356 |
published | 2009-01-13 |
reporter | This script is Copyright (C) 2009-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/35356 |
title | GLSA-200901-08 : Online-Bookmarks: Multiple vulnerabilities |
code |
|
References
- http://freshmeat.net/projects/onlinebookmarks/?branch_id=34962&release_id=174401
- http://freshmeat.net/projects/onlinebookmarks/?branch_id=34962&release_id=174401
- http://secunia.com/advisories/12728/
- http://secunia.com/advisories/12728/
- http://www.securityfocus.com/bid/11305
- http://www.securityfocus.com/bid/11305
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17602
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17602