Micro CMS 'microcms-admin-home.php' Security Bypass Vulnerability
BID:32063
Info
Micro CMS 'microcms-admin-home.php' Security Bypass Vulnerability
| Bugtraq ID: | 32063 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-6553 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | StAkeR |
| Vulnerable: |
Implied By Design Micro CMS 0.3.5 |
| Not Vulnerable: | |
Discussion
Micro CMS 'microcms-admin-home.php' Security Bypass Vulnerability
Micro CMS is prone to a security-bypass vulnerability that occurs when embedded variables are processed.
Attackers may exploit the issue to bypass certain security restrictions to add, edit, or delete user account details.
Versions up to and including Micro CMS 0.3.5 are vulnerable.
Micro CMS is prone to a security-bypass vulnerability that occurs when embedded variables are processed.
Attackers may exploit the issue to bypass certain security restrictions to add, edit, or delete user account details.
Versions up to and including Micro CMS 0.3.5 are vulnerable.
Exploit / POC
Micro CMS 'microcms-admin-home.php' Security Bypass Vulnerability
Attackers can exploit this issue via a browser.
The following exploit is available:
Attackers can exploit this issue via a browser.
The following exploit is available:
Solution / Fix
Micro CMS 'microcms-admin-home.php' Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Micro CMS 'microcms-admin-home.php' Security Bypass Vulnerability
References:
References:
- Micro CMS Homepage (Implied By Design)
- Vendor Homepage (Implied By Design)