Vulnerabilities > CVE-2004-2612 - Unspecified vulnerability in BNC 2.9.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN bnc
nessus
Summary
BNC 2.9.0 only grants access when an incorrect password is provided, which allows remote attackers to use the functionality intended for authorized users.
Nessus
NASL family | Misc. |
NASL id | BNC_AUTH_BYPASS.NASL |
description | The remote host is running a version of the BNC IRC proxy that contains a flaw in its authentication process that accepted only logins with incorrect passwords. An attacker may use this issue to gain access to the remote IRC proxy server. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15703 |
published | 2004-11-13 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15703 |
title | BNC IRC Server Incorrect Password Authentication Bypass |
code |
|
References
- http://secunia.com/advisories/13302
- http://secunia.com/advisories/13302
- http://www.gotbnc.com/changes.html#2.9.1
- http://www.gotbnc.com/changes.html#2.9.1
- http://www.osvdb.org/12144
- http://www.osvdb.org/12144
- http://www.securityfocus.com/bid/11650
- http://www.securityfocus.com/bid/11650
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18103
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18103