PHPSlash Arbitrary Account Privilege Escalation Vulnerability
BID:14189
Info
PHPSlash Arbitrary Account Privilege Escalation Vulnerability
| Bugtraq ID: | 14189 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2005 12:00AM |
| Updated: | Jul 07 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
PHPSlash PHPSlash 0.8 PHPSlash PHPSlash 0.7.2 PHPSlash PHPSlash 0.7.1 PHPSlash PHPSlash 0.6.1 PHPSlash PHPSlash 0.5.3 2 |
| Not Vulnerable: |
PHPSlash PHPSlash 0.8.1 |
Discussion
PHPSlash Arbitrary Account Privilege Escalation Vulnerability
phpSlash is prone to a privilege escalation vulnerability. This issue is due to a design error in the application which utilizes unsafe variables when updating account profile data.
Successful exploitation would result in an attacker gaining control of arbitrary accounts of the affected application. Hijacking of an administrator account could aid in further attacks against the underlying system.
The vendor has addressed this issue in phpSlash 0.8.1; earlier versions are reported vulnerable.
phpSlash is prone to a privilege escalation vulnerability. This issue is due to a design error in the application which utilizes unsafe variables when updating account profile data.
Successful exploitation would result in an attacker gaining control of arbitrary accounts of the affected application. Hijacking of an administrator account could aid in further attacks against the underlying system.
The vendor has addressed this issue in phpSlash 0.8.1; earlier versions are reported vulnerable.
Exploit / POC
PHPSlash Arbitrary Account Privilege Escalation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
PHPSlash Arbitrary Account Privilege Escalation Vulnerability
Solution:
The vendor has addressed this issue in phpSlash version 0.8.1:
PHPSlash PHPSlash 0.5.3 2
PHPSlash PHPSlash 0.6.1
PHPSlash PHPSlash 0.7.1
PHPSlash PHPSlash 0.7.2
PHPSlash PHPSlash 0.8
Solution:
The vendor has addressed this issue in phpSlash version 0.8.1:
PHPSlash PHPSlash 0.5.3 2
-
phpSlash phpslash-0.8.1.tar.gz
http://prdownloads.sourceforge.net/phpslash/phpslash-0.8.1.tar.gz?down load
PHPSlash PHPSlash 0.6.1
-
phpSlash phpslash-0.8.1.tar.gz
http://prdownloads.sourceforge.net/phpslash/phpslash-0.8.1.tar.gz?down load
PHPSlash PHPSlash 0.7.1
-
phpSlash phpslash-0.8.1.tar.gz
http://prdownloads.sourceforge.net/phpslash/phpslash-0.8.1.tar.gz?down load
PHPSlash PHPSlash 0.7.2
-
phpSlash phpslash-0.8.1.tar.gz
http://prdownloads.sourceforge.net/phpslash/phpslash-0.8.1.tar.gz?down load
PHPSlash PHPSlash 0.8
-
phpSlash phpslash-0.8.1.tar.gz
http://prdownloads.sourceforge.net/phpslash/phpslash-0.8.1.tar.gz?down load
References
PHPSlash Arbitrary Account Privilege Escalation Vulnerability
References:
References:
- phpSlash 0.8.1 release notes (phpSlash)
- phpSlash Homepage (phpSlash)
- Re: phpSlash account hijacking vulnerability ([email protected])