Rianxosencabos CMS 'useradmin.php' Access Validation Vulnerability
BID:31296
Info
Rianxosencabos CMS 'useradmin.php' Access Validation Vulnerability
| Bugtraq ID: | 31296 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-4245 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | CWH Underground |
| Vulnerable: |
Rianxosencabos Rianxosencabos CMS 0.9 |
| Not Vulnerable: | |
Discussion
Rianxosencabos CMS 'useradmin.php' Access Validation Vulnerability
Rianxosencabos CMS is prone to a vulnerability that may allow attackers to add and delete arbitrary users.
Successful exploits will compromise the application and possibly the underlying computer. Other attacks are also possible.
Rianxosencabos CMS 0.9 is vulnerable; other versions may also be affected.
Rianxosencabos CMS is prone to a vulnerability that may allow attackers to add and delete arbitrary users.
Successful exploits will compromise the application and possibly the underlying computer. Other attacks are also possible.
Rianxosencabos CMS 0.9 is vulnerable; other versions may also be affected.
Exploit / POC
Rianxosencabos CMS 'useradmin.php' Access Validation Vulnerability
An attacker can exploit this issue through a browser.
An exploit is available.
An attacker can exploit this issue through a browser.
An exploit is available.
Solution / Fix
Rianxosencabos CMS 'useradmin.php' Access Validation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Rianxosencabos CMS 'useradmin.php' Access Validation Vulnerability
References:
References:
- Vendor Homepage (Rianxosencabos)