Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4, allow remote attackers to "falsify authentication credentials," related to the "underlying storage containers."
Link | Tags |
---|---|
http://pear.php.net/package/Auth/download/1.3.0r4 | patch |
http://securitytracker.com/id?1015666 | vdb entry |
http://www.securityfocus.com/archive/1/425796/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24854 | vdb entry |
http://secunia.com/advisories/19301 | third party advisory |
http://www.vupen.com/english/advisories/2006/0696 | vdb entry |
http://www.gentoo.org/security/en/glsa/glsa-200603-13.xml | vendor advisory |
http://pear.php.net/package/Auth/download/1.2.4 | patch |
http://secunia.com/advisories/19008 | third party advisory |
http://www.securityfocus.com/bid/16758 | vdb entry patch vendor advisory |