MeltingIce File System 'admin/adduser.php' Security Bypass Vulnerability
BID:29271
Info
MeltingIce File System 'admin/adduser.php' Security Bypass Vulnerability
| Bugtraq ID: | 29271 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-2348 |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | t0pP8uZz |
| Vulnerable: |
MeltingIce File System MeltingIce File System 1.0 |
| Not Vulnerable: | |
Discussion
MeltingIce File System 'admin/adduser.php' Security Bypass Vulnerability
MeltingIce File System is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
Exploiting this issue may allow an attacker to bypass certain security restrictions and add arbitrary users to the application. This may allow attackers to gain unauthorized access to the application and may aid in further attacks.
The issue affects MeltingIce File System 1.0 and prior versions.
MeltingIce File System is prone to a security-bypass vulnerability because it fails to properly validate user credentials before performing certain actions.
Exploiting this issue may allow an attacker to bypass certain security restrictions and add arbitrary users to the application. This may allow attackers to gain unauthorized access to the application and may aid in further attacks.
The issue affects MeltingIce File System 1.0 and prior versions.
Exploit / POC
MeltingIce File System 'admin/adduser.php' Security Bypass Vulnerability
Attackers can exploit this issue using a browser.
The following proof of concept is available:
Attackers can exploit this issue using a browser.
The following proof of concept is available:
Solution / Fix
MeltingIce File System 'admin/adduser.php' Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MeltingIce File System 'admin/adduser.php' Security Bypass Vulnerability
References:
References:
- MeltingIce File System Project Homepage (MeltingIce File System)