LokiCMS 'admin.php' Security Bypass Vulnerability
BID:29448
Info
LokiCMS 'admin.php' Security Bypass Vulnerability
| Bugtraq ID: | 29448 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-6643 |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | trueend5 |
| Vulnerable: |
LokiCMS LokiCMS 0.3.4 |
| Not Vulnerable: | |
Discussion
LokiCMS 'admin.php' Security Bypass Vulnerability
LokiCMS is prone to a vulnerability that may allow users to bypass authentication to access administrative facilities of the application.
This issue may be related to BID 28985 (LokiCMS 'admin.php' Arbitrary File Deletion Vulnerability).
This issue was reported to affect LokiCMS 0.3.4. Other versions may also be affected.
LokiCMS is prone to a vulnerability that may allow users to bypass authentication to access administrative facilities of the application.
This issue may be related to BID 28985 (LokiCMS 'admin.php' Arbitrary File Deletion Vulnerability).
This issue was reported to affect LokiCMS 0.3.4. Other versions may also be affected.
Exploit / POC
LokiCMS 'admin.php' Security Bypass Vulnerability
Attackers can exploit this issue by issuing a malicious HTTP POST request.
The following exploit code is available:
Attackers can exploit this issue by issuing a malicious HTTP POST request.
The following exploit code is available:
Solution / Fix
LokiCMS 'admin.php' Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
LokiCMS 'admin.php' Security Bypass Vulnerability
References:
References:
- LokiCMS Homepage (LokiCMS)
- LokiCMS Multiple Vulnerabilities through Authorization weakness (Alireza Hassani
)