ByteHoard Username Parameter Multiple Remote Privilege Escalation Vulnerabilities
BID:26578
Info
ByteHoard Username Parameter Multiple Remote Privilege Escalation Vulnerabilities
| Bugtraq ID: | 26578 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2007 12:00AM |
| Updated: | Nov 27 2007 05:53PM |
| Credit: | Ernesto Alvarez is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Bytehoard Bytehoard 2.1 Epsilon Bytehoard Bytehoard 2.1 Delta Bytehoard Bytehoard 2.1 Alpha |
| Not Vulnerable: | |
Discussion
ByteHoard Username Parameter Multiple Remote Privilege Escalation Vulnerabilities
ByteHoard is prone to multiple remote privilege-escalation vulnerabilities because the application fails to properly sanitize user-supplied input before saving it to a session variable.
Successfully exploiting these issues allows remote attackers to gain administrative privileges to the application, which may help them launch other attacks against the underlying computer.
NOTE: Exploiting this issue requires that the PHP directive 'register_globals' be enabled.
ByteHoard is prone to multiple remote privilege-escalation vulnerabilities because the application fails to properly sanitize user-supplied input before saving it to a session variable.
Successfully exploiting these issues allows remote attackers to gain administrative privileges to the application, which may help them launch other attacks against the underlying computer.
NOTE: Exploiting this issue requires that the PHP directive 'register_globals' be enabled.
Exploit / POC
ByteHoard Username Parameter Multiple Remote Privilege Escalation Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
ByteHoard Username Parameter Multiple Remote Privilege Escalation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
ByteHoard Username Parameter Multiple Remote Privilege Escalation Vulnerabilities
References:
References:
- Bytehoard Homepage (Bytehoard)
- two bytehoard 2.1 bugs (Ernesto Alvarez
)