vendor:
My Web Doc
by:
SecurityFocus
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: My Web Doc
Affected Version From: My Web Doc 2000 Final
Affected Version To: My Web Doc 2000 Final
Patch Exists: NO
Related CWE: N/A
CPE: a:mywebdoc:my_web_doc
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
My Web Doc Authentication Bypass Vulnerabilities
My Web Doc is prone to multiple authentication-bypass vulnerabilities. Attackers can leverage these issues to compromise the application, which could aid in other attacks. The vulnerable URLs are: http://www.example.com/mywebdocadd.php3?x, http://www.example.com/mywebdoccalendaradd.php3?x, http://www.example.com/mywebdoclisting.php3?x, http://www.example.com/mywebdocchangepassword.php3?x, http://www.example.com/mywebdocadduser.php3?x, http://www.example.com/mywebdocuserlisting.php3?x
Mitigation:
Ensure that authentication is properly implemented and enforced.