vendor:
Boa web server
by:
Luca "ikki" Carettoni
7.5
CVSS
HIGH
HTTP Basic Authentication Bypass
CWE
Product Name: Boa web server
Affected Version From: 0.93.15
Affected Version To: 0.93.15
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Boa HTTP Basic Authentication Bypass
This exploit allows an attacker to bypass the HTTP basic authentication in Boa web server version 0.93.15 with Intersil Extensions. The attacker can gain unauthorized access to protected resources without providing valid credentials.
Mitigation:
Upgrade to a patched version of Boa web server or use a different web server that does not have this vulnerability.