SlimCMS 'redirect.php' Security Bypass Vulnerability
BID:31736
Info
SlimCMS 'redirect.php' Security Bypass Vulnerability
| Bugtraq ID: | 31736 |
| Class: | Design Error |
| CVE: |
CVE-2008-5708 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | StAkeR |
| Vulnerable: |
SlimCMS SlimCMS 1.0 |
| Not Vulnerable: | |
Discussion
SlimCMS 'redirect.php' Security Bypass Vulnerability
SlimCMS is prone to a vulnerability that allows an attacker to add an arbitrary new user to the system.
An attacker can leverage this vulnerability to gain administrative access to the application.
SlimCMS 1.0.0 is vulnerable; other versions may also be affected.
SlimCMS is prone to a vulnerability that allows an attacker to add an arbitrary new user to the system.
An attacker can leverage this vulnerability to gain administrative access to the application.
SlimCMS 1.0.0 is vulnerable; other versions may also be affected.
Exploit / POC
SlimCMS 'redirect.php' Security Bypass Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
SlimCMS 'redirect.php' Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].