|
BookMark4U contains a flaw that may allow an attacker to bypass authentication. The issue is due to the program allowing authentication based on IP address, rather than password. By spoofing an IP address or coming from the same IP as the target (e.g., same ISP, same proxy), an attacker can access the application without providing the password.
|