HTTP: ACal Calendar Project 2.2.5 Authentication Bypass

This signature detects attempts to exploit a known vulnerability against ACal Calendar Project 2.2.5. A successful attack can lead to unauthorized access.

Extended Description

login.php in ACal Calendar Project 2.2.5 allows remote attackers to bypass authentication by setting the ACalAuthenticate cookie variable to "inside".

Affected Products

Acal calendar_project

References

CVE: CVE-2006-0182

Short Name
HTTP:PHP:ACAL-AUTH-BYPASS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
2.2.5 ACal Authentication Bypass CVE-2006-0182 Calendar Project
Release Date
04/23/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Acal

CVSS Score

7.5

Found a potential security threat?