Easy Photo Gallery 'useradmin.php' Access Validation Vulnerability
BID:31161
Info
Easy Photo Gallery 'useradmin.php' Access Validation Vulnerability
| Bugtraq ID: | 31161 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-4167 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2008 12:00AM |
| Updated: | May 07 2015 05:24PM |
| Credit: | Stack |
| Vulnerable: |
Easy Photo Gallery Easy Photo Gallery 2.1 |
| Not Vulnerable: | |
Discussion
Easy Photo Gallery 'useradmin.php' Access Validation Vulnerability
Easy Photo Gallery is prone to a vulnerability that may allow attackers to add and delete arbitrary users.
Successful exploits will compromise the application and possibly the underlying computer. Other attacks are also possible.
Easy Photo Gallery 2.1 is vulnerable; other versions may also be affected.
Easy Photo Gallery is prone to a vulnerability that may allow attackers to add and delete arbitrary users.
Successful exploits will compromise the application and possibly the underlying computer. Other attacks are also possible.
Easy Photo Gallery 2.1 is vulnerable; other versions may also be affected.
Exploit / POC
Easy Photo Gallery 'useradmin.php' Access Validation Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Easy Photo Gallery 'useradmin.php' Access Validation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Easy Photo Gallery 'useradmin.php' Access Validation Vulnerability
References:
References:
- Easy Photo Gallery SourceForge Page (Easy Photo Gallery)