activeWeb contentserver Permissions Bypass Weakness
BID:24900
Info
activeWeb contentserver Permissions Bypass Weakness
| Bugtraq ID: | 24900 |
| Class: | Design Error |
| CVE: |
CVE-2007-3018 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2007 12:00AM |
| Updated: | Mar 19 2015 09:48AM |
| Credit: | RedTeam Pentesting GmbH is credited with the discovery of this vulnerability. |
| Vulnerable: |
ActiveWebSoftwares.com contentserver 5.6.2929 |
| Not Vulnerable: |
ActiveWebSoftwares.com contentserver 5.6.2964 |
Discussion
activeWeb contentserver Permissions Bypass Weakness
activeWeb contentserver is prone to a weakness that may allow an attacker to write files to unauthorized locations. A design error in the application allows editor accounts to write files to unauthorized locations, regardless of the permissions established for the account.
This weakness is confirmed in versions prior to contentserver 5.6.2964.
activeWeb contentserver is prone to a weakness that may allow an attacker to write files to unauthorized locations. A design error in the application allows editor accounts to write files to unauthorized locations, regardless of the permissions established for the account.
This weakness is confirmed in versions prior to contentserver 5.6.2964.
Exploit / POC
activeWeb contentserver Permissions Bypass Weakness
An exploit is not required. Editor privileges are required to exploit this issue.
An exploit is not required. Editor privileges are required to exploit this issue.
Solution / Fix
activeWeb contentserver Permissions Bypass Weakness
Solution:
Reports indicate that contentserver 5.6.2964 is not affected by these issues, but Symantec was unable to verify this information. Please contact the vendor for more information.
Solution:
Reports indicate that contentserver 5.6.2964 is not affected by these issues, but Symantec was unable to verify this information. Please contact the vendor for more information.
References
activeWeb contentserver Permissions Bypass Weakness
References:
References:
- Vendor Homepage (contentserver activeWeb)
- ActiveWeb Contentserver CMS Editor Permission Settings Problem (RedTeam Pentesting GmbH)
- Advisory: ActiveWeb Contentserver CMS Editor Permission Settings Problem (RedTeam Pentesting GmbH )