Surfnet 1.31 - Unauthorized Account Depositing



EKU-ID: 28952 CVE: OSVDB-16994 OSVDB-ID:
Author: Rift_XT Published: 2004-01-02 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/9347/info

Surfnet kiosks are prone to a vulnerability that may permit kiosk users to deposit extra time into kiosk accounts. This reportedly occurs when a user attempts to authenticate to the kiosk, causing their time to be doubled for each attempt.

C:\Surfnet\WWWRoot\CMD_Existing_Account_Attempt:Login=Username:Password=Password