Description
Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2006-0447 | Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T16:34:14.646Z
Reserved: 2006-01-26T00:00:00.000Z
Link: CVE-2006-0440
No data.
Status : Modified
Published: 2006-01-26T22:03:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2006-0440
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD