Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an empty password during the login sequence.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/30468 | third party advisory vendor advisory |
http://www.vupen.com/english/advisories/2008/1710 | vdb entry |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=483770 | |
http://www.openwall.com/lists/oss-security/2008/05/31/3 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/42798 | vdb entry |
http://ikiwiki.info/news/version_2.48/index.html | |
http://www.securityfocus.com/bid/29479 | vdb entry |
http://ikiwiki.info/security/#index33h2 |