CVE
- Id
- 10680
- CVE No.
- CVE-2004-2254
- Status
- Candidate
- Description
- SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.
- Phase
- Assigned (20050717)
- Votes
- None (candidate not yet proposed)
- Comments