Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Dolphin Authentication Bypass Vulnerability

Information

Severity

Severity

Medium

Family

Family

Web application abuses

CVSSv2 Base

CVSSv2 Base

6.4

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:N

Solution Type

Solution Type

Vendor Patch

Created

Created

7 years ago

Modified

Modified

5 years ago

Summary

Dolphin is prone to an authentication bypass vulnerability.

Insight

Insight

Dolphin uses strcmp() to check the password in admin.inc.php. If an array is provided instead of a string in the cookie value 'memberPassword, authentication can be bypassed.

Affected Software

Affected Software

BoonEx Dolphin 7.3.2 and prior.

Detection Method

Detection Method

Tries to bypass the authentication and access the admin panel.

Solution

Solution

Update to 7.3.3 or later.