Flip Unauthorized Administrative Account Creation Security Bypass Vulnerability
BID:25746
Info
Flip Unauthorized Administrative Account Creation Security Bypass Vulnerability
| Bugtraq ID: | 25746 |
| Class: | Access Validation Error |
| CVE: |
CVE-2007-5062 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2007 12:00AM |
| Updated: | May 07 2015 05:35PM |
| Credit: | undefined1_ discovered this issue. |
| Vulnerable: |
Flipsource Flip 3.0 |
| Not Vulnerable: | |
Discussion
Flip Unauthorized Administrative Account Creation Security Bypass Vulnerability
Flip is prone to a security-bypass vulnerability because it fails to perform adequate authentication checks when creating administrative accounts.
An attacker can exploit this issue to gain unauthorized administrator access to the application.
Flip 3.0 is vulnerable; other versions may also be affected.
Flip is prone to a security-bypass vulnerability because it fails to perform adequate authentication checks when creating administrative accounts.
An attacker can exploit this issue to gain unauthorized administrator access to the application.
Flip 3.0 is vulnerable; other versions may also be affected.
Exploit / POC
Flip Unauthorized Administrative Account Creation Security Bypass Vulnerability
Attackers can exploit this issue via a browser.
The following exploit is available:
Attackers can exploit this issue via a browser.
The following exploit is available:
Solution / Fix
Flip Unauthorized Administrative Account Creation Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Flip Unauthorized Administrative Account Creation Security Bypass Vulnerability
References:
References:
- Vendor Homepage (Flipsource)