Vulnerabilities > CVE-2007-2713 - Authentication Bypass vulnerability in IFDate Administrative

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
ifusionservices
critical

Summary

ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request for the admin/ URI.

Vulnerable Configurations

Part Description Count
Application
Ifusionservices
2