ZaireWeb Solutions Newsletter ZWS Administrative Interface Authentication Bypass Vulnerability
BID:10605
Info
ZaireWeb Solutions Newsletter ZWS Administrative Interface Authentication Bypass Vulnerability
| Bugtraq ID: | 10605 |
| Class: | Design Error |
| CVE: |
CVE-2004-0621 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 24 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | This vulnerability was reported by GaMeS. |
| Vulnerable: |
ZaireWeb Solutions Newsletter ZWS |
| Not Vulnerable: | |
Discussion
ZaireWeb Solutions Newsletter ZWS Administrative Interface Authentication Bypass Vulnerability
Newsletter ZWS is reported prone to an administrative interface authentication bypass vulnerability. The vulnerability exists due to a design error in the implementation of the authentication system for the interface. The flaw allows a user to set their privileges through a URI parameter passed to the 'admin.php' script.
Newsletter ZWS is reported prone to an administrative interface authentication bypass vulnerability. The vulnerability exists due to a design error in the implementation of the authentication system for the interface. The flaw allows a user to set their privileges through a URI parameter passed to the 'admin.php' script.
Exploit / POC
ZaireWeb Solutions Newsletter ZWS Administrative Interface Authentication Bypass Vulnerability
The following example is available:
http://www.example.com/newsletter/admin.php?f=list_user&uname=test&ulevel=1
The following example is available:
http://www.example.com/newsletter/admin.php?f=list_user&uname=test&ulevel=1
Solution / Fix
ZaireWeb Solutions Newsletter ZWS Administrative Interface Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ZaireWeb Solutions Newsletter ZWS Administrative Interface Authentication Bypass Vulnerability
References:
References:
- ZWS Newsletter & Mailing List Manager (GaMeS GaMeS
)