WebPortal CMS 'action.php' Unauthorized Access Vulnerability
BID:27145
Info
WebPortal CMS 'action.php' Unauthorized Access Vulnerability
| Bugtraq ID: | 27145 |
| Class: | Design Error |
| CVE: |
CVE-2008-0141 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 04 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | The:Paradox is credited with discovering this issue. |
| Vulnerable: |
WebPortal WebPortal CMS 0.6 |
| Not Vulnerable: | |
Discussion
WebPortal CMS 'action.php' Unauthorized Access Vulnerability
WebPortal CMS is prone to a vulnerability that results in unauthorized access. This issue occurs because the application generates predictable passwords for users who forget their password.
Attackers can leverage this issue to change the password of arbitrary user accounts and gain unauthorized access to the application.
WebPortal CMS 0.6 is vulnerable; other versions may also be affected.
WebPortal CMS is prone to a vulnerability that results in unauthorized access. This issue occurs because the application generates predictable passwords for users who forget their password.
Attackers can leverage this issue to change the password of arbitrary user accounts and gain unauthorized access to the application.
WebPortal CMS 0.6 is vulnerable; other versions may also be affected.
Exploit / POC
WebPortal CMS 'action.php' Unauthorized Access Vulnerability
Attackers can leverage this issue via a browser.
The following exploit code is available:
Attackers can leverage this issue via a browser.
The following exploit code is available:
Solution / Fix
WebPortal CMS 'action.php' Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].