View Issue Details

IDProjectCategoryView StatusLast Update
0000209Main CAcert Websitesource codepublic2013-01-14 08:06
Reporterblshkv Assigned Toduane  
PrioritynormalSeveritymajorReproducibilityalways
Status closedResolutionfixed 
Fixed in Version2006 
Summary0000209: unauthenticated access on the test1 website
DescriptionIt's possible to manipulate (vew/change/delete) any user data without
without being loged in by anyone.

https://www.test1.cacert.at/account/43.php
https://www.test1.cacert.at/account/43.php?userid=176
(add "assurance" parameter to delete)
https://www.test1.cacert.at/account/53.php?ccid=1
and more.

Don't relay on .htaccess and don't keep such files in the webroot.
TagsNo tags attached.
Reviewed by
Test Instructions

Relationships

duplicate of 0000152 closed I spy with my little eye something beginning with U ... 

Activities

bluec

2006-04-20 18:43

manager   ~0000157

This bug has been fixed for the main website and the test1 site hasn't been updated yet.

duane

2006-04-21 06:31

developer   ~0000164

files moved from webroot

bluec

2006-04-24 05:42

manager   ~0000197

Change not yet visible in tarball.

bluec

2006-05-07 21:11

manager   ~0000218

The updated tarball doesn't show the files in the right place!

Please reassign this report to me when updated.

duane

2006-08-14 03:36

developer   ~0000411

This was already fixed in another bug when we shifted all display code from out of the webroot...

Issue History

Date Modified Username Field Change
2006-04-16 11:07 blshkv New Issue
2006-04-20 18:37 bluec Relationship added duplicate of 0000152
2006-04-20 18:43 bluec Note Added: 0000157
2006-04-21 06:31 duane Status new => closed
2006-04-21 06:31 duane Note Added: 0000164
2006-04-21 06:31 duane Resolution open => fixed
2006-04-21 06:31 duane Fixed in Version => production
2006-04-24 05:42 bluec Note Added: 0000197
2006-04-24 05:42 bluec Assigned To => bluec
2006-04-24 05:42 bluec Status closed => needs work
2006-05-07 21:11 bluec Note Added: 0000218
2006-05-07 21:11 bluec Assigned To bluec => duane
2006-08-14 03:36 duane Status needs work => closed
2006-08-14 03:36 duane Note Added: 0000411
2006-08-14 03:37 duane Fixed in Version production =>
2010-07-27 15:59 Sourcerer View Status private => public
2013-01-14 08:06 Werner Dworak Fixed in Version => 2006