Search This Blog

Monday, May 21, 2007

[NEWS] Authentication Bypass in Rational Soft's Hidden Administrator

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html


- - - - - - - - -

Authentication Bypass in Rational Soft's Hidden Administrator
------------------------------------------------------------------------


SUMMARY

rewterz has discovered a critical vulnerability in Hidden Administrator.
This vulnerability allows a remote attacker to execute arbitrary code in
the context of the user who executed Hidden Administrator.

DETAILS

Vulnerable Systems:
* Hidden Administrator version 1.7 and prior

Authentication mechanism of Hidden Administrator can be bypassed with ease
via this vulnerability. With authentication bypassed at the Hidden
Administrator server, any malicious user can cause Hidden Administrator to
run arbitrary code and assume full control of the system on which Hidden
Administrator is running.


ADDITIONAL INFORMATION

The information has been provided by <mailto:advisories@rewterz.com>
rewterz security team.

========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

No comments: