Vulnerability Description
SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netwin | Surgeldap | 1.0a |
References
- http://netwinsite.com/surgeldap/updates.htmPatch
- http://secunia.com/advisories/11549ExploitVendor Advisory
- http://securitytracker.com/alerts/2004/May/1010113.htmlExploitPatch
- http://securitytracker.com/id?1010068Exploit
- http://www.osvdb.org/5890ExploitPatch
- http://www.securityfocus.com/bid/10294Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16076
- http://netwinsite.com/surgeldap/updates.htmPatch
- http://secunia.com/advisories/11549ExploitVendor Advisory
- http://securitytracker.com/alerts/2004/May/1010113.htmlExploitPatch
- http://securitytracker.com/id?1010068Exploit
- http://www.osvdb.org/5890ExploitPatch
- http://www.securityfocus.com/bid/10294Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16076
FAQ
What is CVE-2004-2254?
CVE-2004-2254 is a vulnerability with a CVSS score of 7.5 (HIGH). SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified ...
How severe is CVE-2004-2254?
CVE-2004-2254 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-2254?
Check the references section above for vendor advisories and patch information. Affected products include: Netwin Surgeldap.