>> PhpWiki "checkPass()" Function Empty Password Processing Security Bypass Issue
Title : PhpWiki "checkPass()" Function Empty Password Processing Security Bypass Issue VUPEN ID : VUPEN/ADV-2007-2144 CVE ID : CVE-2007-3193
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-06-12
Technical Description
A vulnerability has been identified in PhpWiki, which could be exploited by attackers to bypass security checks. This issue is caused by an error in the "checkPass()" [lib/WikiUser/LDAP.php] function when handling empty passwords, which could be exploited by unauthenticated attackers to gain unauthorized access to certain LDAP implementations.