Micro News 'admin.php' Authentication Bypass Vulnerability
BID:27288
Info
Micro News 'admin.php' Authentication Bypass Vulnerability
| Bugtraq ID: | 27288 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-0377 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 15 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
phptoys.com Micro News 0 |
| Not Vulnerable: | |
Discussion
Micro News 'admin.php' Authentication Bypass Vulnerability
Micro News is prone to an authentication-bypass vulnerability because it fails to verify access to administrative segments of the application.
An attacker can exploit this issue to gain unauthorized access to the affected application. This may lead to further attacks.
Micro News is prone to an authentication-bypass vulnerability because it fails to verify access to administrative segments of the application.
An attacker can exploit this issue to gain unauthorized access to the affected application. This may lead to further attacks.
Exploit / POC
Micro News 'admin.php' Authentication Bypass Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
Micro News 'admin.php' Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Micro News 'admin.php' Authentication Bypass Vulnerability
References:
References: