The server in Babo Violent 2 2.08.00 and earlier does not properly implement password protection, which might allow remote attackers to bypass authentication by reconnecting after a connection closes.
Link | Tags |
---|---|
http://securityreason.com/securityalert/3024 | third party advisory |
http://www.securityfocus.com/archive/1/476520/100/0/threaded | mailing list |
http://aluigi.altervista.org/adv/bv2x-adv.txt |