Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an empty password during the login sequence.
2008-06-03T15:32:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ikiwiki | ikiwiki | 1.5 | Yes |
Application | ikiwiki | ikiwiki | 1.34 | Yes |
Application | ikiwiki | ikiwiki | 1.34.1 | Yes |
Application | ikiwiki | ikiwiki | 1.34.2 | Yes |
Application | ikiwiki | ikiwiki | 1.35 | Yes |
Application | ikiwiki | ikiwiki | 1.36 | Yes |
Application | ikiwiki | ikiwiki | 1.37 | Yes |
Application | ikiwiki | ikiwiki | 1.38 | Yes |
Application | ikiwiki | ikiwiki | 1.39 | Yes |
Application | ikiwiki | ikiwiki | 1.40 | Yes |
Application | ikiwiki | ikiwiki | 1.41 | Yes |
Application | ikiwiki | ikiwiki | 1.42 | Yes |
Application | ikiwiki | ikiwiki | 1.43 | Yes |
Application | ikiwiki | ikiwiki | 1.44 | Yes |
Application | ikiwiki | ikiwiki | 1.45 | Yes |
Application | ikiwiki | ikiwiki | 1.46 | Yes |
Application | ikiwiki | ikiwiki | 1.47 | Yes |
Application | ikiwiki | ikiwiki | 1.48 | Yes |
Application | ikiwiki | ikiwiki | 1.49 | Yes |
Application | ikiwiki | ikiwiki | 1.51 | Yes |
Application | ikiwiki | ikiwiki | 2.0 | Yes |
Application | ikiwiki | ikiwiki | 2.1 | Yes |
Application | ikiwiki | ikiwiki | 2.2 | Yes |
Application | ikiwiki | ikiwiki | 2.3 | Yes |
Application | ikiwiki | ikiwiki | 2.4 | Yes |
Application | ikiwiki | ikiwiki | 2.5 | Yes |
Application | ikiwiki | ikiwiki | 2.6 | Yes |
Application | ikiwiki | ikiwiki | 2.7 | Yes |
Application | ikiwiki | ikiwiki | 2.8 | Yes |
Application | ikiwiki | ikiwiki | 2.9 | Yes |
Application | ikiwiki | ikiwiki | 2.10 | Yes |
Application | ikiwiki | ikiwiki | 2.11 | Yes |
Application | ikiwiki | ikiwiki | 2.12 | Yes |
Application | ikiwiki | ikiwiki | 2.13 | Yes |
Application | ikiwiki | ikiwiki | 2.14 | Yes |
Application | ikiwiki | ikiwiki | 2.15 | Yes |
Application | ikiwiki | ikiwiki | 2.16 | Yes |
Application | ikiwiki | ikiwiki | 2.17 | Yes |
Application | ikiwiki | ikiwiki | 2.18 | Yes |
Application | ikiwiki | ikiwiki | 2.19 | Yes |
Application | ikiwiki | ikiwiki | 2.20 | Yes |
Application | ikiwiki | ikiwiki | 2.30 | Yes |
Application | ikiwiki | ikiwiki | 2.31 | Yes |
Application | ikiwiki | ikiwiki | 2.31.1 | Yes |
Application | ikiwiki | ikiwiki | 2.31.2 | Yes |
Application | ikiwiki | ikiwiki | 2.31.3 | Yes |
Application | ikiwiki | ikiwiki | 2.40 | Yes |
Application | ikiwiki | ikiwiki | 2.41 | Yes |
Application | ikiwiki | ikiwiki | 2.42 | Yes |
Application | ikiwiki | ikiwiki | 2.43 | Yes |
Application | ikiwiki | ikiwiki | 2.44 | Yes |
Application | ikiwiki | ikiwiki | 2.47 | Yes |