Subdreamer CMS Comments Function Security Bypass Vulnerability
BID:26595
Info
Subdreamer CMS Comments Function Security Bypass Vulnerability
| Bugtraq ID: | 26595 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2007 12:00AM |
| Updated: | May 20 2008 10:44PM |
| Credit: | Nicholas Hillebran and Mr_Bob are credited with the discovery of this vulnerability. |
| Vulnerable: |
Subdreamer Subdreamer CMS 2.4.3 .1 |
| Not Vulnerable: | |
Discussion
Subdreamer CMS Comments Function Security Bypass Vulnerability
Subdreamer CMS is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
A successful attack will allow an unauthorized attacker to post arbitrary comments when anonymous posting is disabled.
This issue affects Subdreamer CMS 2.4.3.1 and prior versions.
Subdreamer CMS is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
A successful attack will allow an unauthorized attacker to post arbitrary comments when anonymous posting is disabled.
This issue affects Subdreamer CMS 2.4.3.1 and prior versions.
Exploit / POC
Subdreamer CMS Comments Function Security Bypass Vulnerability
An attacker can exploit this issue through a browser.
An attacker can exploit this issue through a browser.
Solution / Fix
Subdreamer CMS Comments Function Security Bypass Vulnerability
Solution:
The vendor has released updates. Please contact the vendor for information on obtaining and applying the updates.
Solution:
The vendor has released updates. Please contact the vendor for information on obtaining and applying the updates.
References
Subdreamer CMS Comments Function Security Bypass Vulnerability
References:
References:
- Security Flaw: Is possible to Insert a Comment with access denied! (Nicholas Hillebran (Mr_Bob))
- Subdreamer Homepage (Subdreamer)