Extreme CMS Options.PHP Authentication Bypass Vulnerability
BID:21118
Info
Extreme CMS Options.PHP Authentication Bypass Vulnerability
| Bugtraq ID: | 21118 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2006 12:00AM |
| Updated: | Nov 20 2006 07:55PM |
| Credit: | r0ut3r is credited with the discovery of this vulnerability. |
| Vulnerable: |
Extreme CMS Extreme CMS 0.9 |
| Not Vulnerable: | |
Discussion
Extreme CMS Options.PHP Authentication Bypass Vulnerability
Extreme CMS is prone to an authentication-bypass vulnerability because it fails to authenticate users before providing access to sensitive information.
Exploiting this issue could allow an attacker to change the passwords of legitimate users to gain elevated privileges. A successful exploit could prevent legitimate users from accessing the application and may result in the compromise of the application.
Extreme CMS 0.9 is reported vulnerable to this issue; other versions may be affected as well.
Extreme CMS is prone to an authentication-bypass vulnerability because it fails to authenticate users before providing access to sensitive information.
Exploiting this issue could allow an attacker to change the passwords of legitimate users to gain elevated privileges. A successful exploit could prevent legitimate users from accessing the application and may result in the compromise of the application.
Extreme CMS 0.9 is reported vulnerable to this issue; other versions may be affected as well.
Exploit / POC
Extreme CMS Options.PHP Authentication Bypass Vulnerability
An attacker can exploit this issue via a web client.
An attacker can exploit this issue via a web client.
Solution / Fix
Extreme CMS Options.PHP Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Extreme CMS Options.PHP Authentication Bypass Vulnerability
References:
References:
- Extreme CMS Home Page (Extreme CMS)