Surfnet 1.31 - Unauthorized Account Depositing

EDB-ID:

23511

CVE:



Author:

Rift_XT

Type:

local


Platform:

Windows

Date:

2004-01-02


source: https://www.securityfocus.com/bid/9347/info

Surfnet kiosks are prone to a vulnerability that may permit kiosk users to deposit extra time into kiosk accounts. This reportedly occurs when a user attempts to authenticate to the kiosk, causing their time to be doubled for each attempt. 

C:\Surfnet\WWWRoot\CMD_Existing_Account_Attempt:Login=Username:Password=Password