SmartSiteCMS Admin.PHP Authentication Bypass Vulnerability
BID:19434
Info
SmartSiteCMS Admin.PHP Authentication Bypass Vulnerability
| Bugtraq ID: | 19434 |
| Class: | Design Error |
| CVE: |
CVE-2006-7074 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2006 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | Paulino Calderon is credited with the discovery of this vulnerability. |
| Vulnerable: |
smartSiteCMS SmartSiteCMS 1.0 |
| Not Vulnerable: | |
Discussion
SmartSiteCMS Admin.PHP Authentication Bypass Vulnerability
SmartSiteCMS is prone to an authentication-bypass vulnerability because the affected script fails to verify cookies properly and to perform other authentication checks. This lets a malicious user simply create an appropriately named cookie that allows administrative access to the application.
An attacker can exploit this issue to bypass authentication and gain admin access to the affected application. This could aid in further attacks on the affected computer.
SmartSiteCMS v 1.0 is vulnerable. Earlier Beta versions may also be affected.
SmartSiteCMS is prone to an authentication-bypass vulnerability because the affected script fails to verify cookies properly and to perform other authentication checks. This lets a malicious user simply create an appropriately named cookie that allows administrative access to the application.
An attacker can exploit this issue to bypass authentication and gain admin access to the affected application. This could aid in further attacks on the affected computer.
SmartSiteCMS v 1.0 is vulnerable. Earlier Beta versions may also be affected.
Exploit / POC
SmartSiteCMS Admin.PHP Authentication Bypass Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
SmartSiteCMS Admin.PHP Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SmartSiteCMS Admin.PHP Authentication Bypass Vulnerability
References:
References:
- SmartSiteCMS Project Page (SmartSiteCMS)