Vulnerabilities > CVE-2006-0868 - SQL Injection vulnerability in PEAR::Auth

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
pear
nessus

Summary

Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4, allow remote attackers to "falsify authentication credentials," related to the "underlying storage containers."

Nessus

NASL familyGentoo Local Security Checks
NASL idGENTOO_GLSA-200603-13.NASL
descriptionThe remote host is affected by the vulnerability described in GLSA-200603-13 (PEAR-Auth: Potential authentication bypass) Matt Van Gundy discovered that PEAR-Auth did not correctly validate data passed to the DB and LDAP containers. Impact : A remote attacker could possibly exploit this vulnerability to bypass the authentication mechanism by injecting specially crafted input to the underlying storage containers. Workaround : There is no known workaround at this time.
last seen2020-06-01
modified2020-06-02
plugin id21094
published2006-03-18
reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/21094
titleGLSA-200603-13 : PEAR-Auth: Potential authentication bypass