Total Tests:

Authentication Bypass Vulnerability in phpLiterAdmin

Advisory ID:HTB22653
Product:phpLiterAdmin
Vendor:phpLiterAdmin
Vulnerable Versions:1.0 RC1
Tested Version:1.0 RC1
Advisory Publication:October 13, 2010 [without technical details]
Vendor Notification:October 13, 2010
Public Disclosure:October 27, 2010
Latest Update:October 14, 2010
Vulnerability Type:Improper Authentication [CWE-287]
Risk Level:High
CVSSv2 Base Score:7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Solution Status:Fixed by Vendor
Discovered and Provided:High-Tech Bridge Security Research Lab
 

Advisory Details:

High-Tech Bridge SA Security Research Lab has discovered vulnerability in phpLiterAdmin which could be exploited to bypass authentication mechanism and gain unauthorized access to the application.

1) Authentication Bypass Vulnerability in phpLiterAdmin
The vulnerability exists due to a design error in authentication mechanism. A remote attacker can modify the "phpLiterAdmin432" cookie value and gain unauthorized access to the application. Successful exploitation requires knowledge of existing usernames.
Exploitation example:
phpLiterAdmin432=a:2:{s:8:"username"%3bs:5:"admin"%3bs:8:"password"%3bb:1%3b };

How to Detect Improper Authentication Vulnerabilities
Website Security Test
  • GDPR & PCI DSS Test
  • Website CMS Security Test
  • CSP & HTTP Headers Check
  • WordPress & Drupal Scanning
Try For Free

Solution:
Fixed in phpLiterAdmin v1.0 RC1.1.


References:
[1] High-Tech Bridge Advisory HTB22653 - https://www.immuniweb.com/advisory/HTB22653 - Authentication Bypass Vulnerability in phpLiterAdmin
[2] phpLiterAdmin - http://code.google.com/p/phpliteradmin/ - phpLiterAdmin is an SQLite Manager which uses PHP.
[3] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to developers and security practitioners, CWE is a formal list of software weakness types.
Previous Security Advisories with CWE-287:

HTB22519: Multiple Vulnerabilities in DT Centrepiece


Have additional information to submit?
Please feel free to send us any additional information related to this Advisory, such as vulnerable versions, additional exploitation details and conditions, patches and other relevant details.
Book a Call Ask a Question
Close
Talk to ImmuniWeb Experts
ImmuniWeb AI Platform
Have a technical question?

Our security experts will answer within
one business day. No obligations.

Have a sales question?
Email:
Tel: +41 22 560 6800 (Switzerland)
Tel: +1 720 605 9147 (USA)
*
*
*
Your data will stay private and confidential