CVE-2012-6710

ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empty array) in an action=login request to index.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:extplorer:extplorer:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:46

Type Values Removed Values Added
References () http://itsecuritysolutions.org/2012-12-31-eXtplorer-v2.1-authentication-bypass-vulnerability - Exploit, Third Party Advisory () http://itsecuritysolutions.org/2012-12-31-eXtplorer-v2.1-authentication-bypass-vulnerability - Exploit, Third Party Advisory
References () http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201212-371 - Third Party Advisory () http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-201212-371 - Third Party Advisory
References () https://www.securityfocus.com/bid/57058 - Third Party Advisory, VDB Entry () https://www.securityfocus.com/bid/57058 - Third Party Advisory, VDB Entry

Information

Published : 2018-10-07 18:29

Updated : 2024-11-21 01:46


NVD link : CVE-2012-6710

Mitre link : CVE-2012-6710

CVE.ORG link : CVE-2012-6710


JSON object : View

Products Affected

extplorer

  • extplorer
CWE
CWE-287

Improper Authentication