Netious CMS Authorization Bypass Vulnerability
BID:19421
CVE-2006-4048 |Info
Netious CMS Authorization Bypass Vulnerability
| Bugtraq ID: | 19421 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2006 12:00AM |
| Updated: | Aug 08 2006 08:55PM |
| Credit: | Jacek Wlodarczyk has been credited with the discovery of this vulnerability. |
| Vulnerable: |
Netious CMS Netious CMS 0.4 |
| Not Vulnerable: | |
Discussion
Netious CMS Authorization Bypass Vulnerability
Netious CMS is prone to an authorization bypass vulnerability because it fails to properly authenticate administrative users.
A successful exploit will allow the attacker to gain administrative access and to manipulate sensitive information. Other attacks are also possible.
Netious CMS is prone to an authorization bypass vulnerability because it fails to properly authenticate administrative users.
A successful exploit will allow the attacker to gain administrative access and to manipulate sensitive information. Other attacks are also possible.
Exploit / POC
Netious CMS Authorization Bypass Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Netious CMS Authorization Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.