<title>PhpWiki: Authentication bypass</title>
A vulnerability has been discovered in PhpWiki authentication mechanism.
<announced>September 18, 2007</announced>
<revised>September 18, 2007: 01</revised>
PhpWiki is an application that creates a web site where anyone can edit
the pages through HTML forms.
The PhpWiki development team reported an authentication error within
the file lib/WikiUser/LDAP.php when binding to an LDAP server with an
empty password.
<impact type="low">
A remote attacker could provide an empty password when authenticating.
Depending on the LDAP implementation used, this could bypass the
PhpWiki authentication mechanism and grant the attacker access to the
There is no known workaround at this time.
All PhpWiki users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=www-apps/phpwiki-1.3.14&quot;</code>
<uri link="">CVE-2007-3193</uri>
