packetstormsecurity.com
http://packetstormsecurity.com/files/128853/Filemaker-Login-Bypass-Privilege-Escalation.html CVE-2014-8347
HIGH
Filemaker Pro 13.03 / Advanced 12.04 - Authentication Bypass / Privilege Escalation
Record summary
CVE-2014-8347 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advanced 12.04, which could let a malicious user obtain elevated privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBFilemaker Pro 13.03 / Advanced 12.04 - Authentication Bypass / Privilege EscalationExploitDB exploitby Giuseppe D'AmoreNot analyzed1 file
References
6exploit-db.com
http://www.exploit-db.com/exploits/35077 exchange.xforce.ibmcloud.com
https://exchange.xforce.ibmcloud.com/vulnerabilities/97780 lists.openwall.net
https://lists.openwall.net/bugtraq/2014/10/27/4 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-8347 securityfocus.com
https://www.securityfocus.com/archive/1/533814