PHProjekt Arbitrary User Modification Vulnerability
BID:3239
Info
PHProjekt Arbitrary User Modification Vulnerability
| Bugtraq ID: | 3239 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2001 12:00AM |
| Updated: | Aug 26 2001 12:00AM |
| Credit: | This vulnerability was discovered by Martin Mayrhofer and submitted to BugTraq by "Albrecht Guenther" <[email protected]> on August 26th, 2001. |
| Vulnerable: |
PHProjekt PHProjekt 2.4 PHProjekt PHProjekt 2.3 PHProjekt PHProjekt 2.2 PHProjekt PHProjekt 2.1 a PHProjekt PHProjekt 2.1 PHProjekt PHProjekt 2.0.1 PHProjekt PHProjekt 2.0 |
| Not Vulnerable: |
PHProjekt PHProjekt 2.4 a |
Discussion
PHProjekt Arbitrary User Modification Vulnerability
PHProjekt is a freely available, open source PHP Groupware package. It is actively maintained by the PHProjekt Development Team.
PHProjekt(versions prior to 2.4a) is prone to an input validation problem which will allow remote attackers to view, modify and delete arbitrary user data. This is done by changing the ID number in the URL.
PHProjekt is a freely available, open source PHP Groupware package. It is actively maintained by the PHProjekt Development Team.
PHProjekt(versions prior to 2.4a) is prone to an input validation problem which will allow remote attackers to view, modify and delete arbitrary user data. This is done by changing the ID number in the URL.
Exploit / POC
PHProjekt Arbitrary User Modification Vulnerability
This issue can be exploited with a web browser.
This issue can be exploited with a web browser.