eZ Publish '/user/register' Remote Privilege Escalation Vulnerability
BID:32762
Info
eZ Publish '/user/register' Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 32762 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2008 12:00AM |
| Updated: | Dec 12 2008 08:31PM |
| Credit: | Reported by the vendor |
| Vulnerable: |
eZ Systems eZ publish 4.0 eZ Systems eZ publish 3.10 eZ Systems eZ publish 3.9.3 eZ Systems eZ publish 3.9.3 eZ Systems eZ publish 3.9.2 eZ Systems eZ publish 3.9.1 eZ Systems eZ publish 3.9 |
| Not Vulnerable: |
eZ Systems eZ publish 4.0.1 eZ Systems eZ publish 3.10.1 eZ Systems eZ publish 3.9.5 |
Discussion
eZ Publish '/user/register' Remote Privilege Escalation Vulnerability
eZ Publish is prone to a remote privilege-escalation vulnerability.
Attackers can exploit this issue to gain administrative access to the affected application. Successful exploits will compromise the application.
Versions prior to eZ Publish 3.9.5, 3.10.1, and 4.0.1 are vulnerable.
eZ Publish is prone to a remote privilege-escalation vulnerability.
Attackers can exploit this issue to gain administrative access to the affected application. Successful exploits will compromise the application.
Versions prior to eZ Publish 3.9.5, 3.10.1, and 4.0.1 are vulnerable.
Exploit / POC
eZ Publish '/user/register' Remote Privilege Escalation Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
eZ Publish '/user/register' Remote Privilege Escalation Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
eZ Publish '/user/register' Remote Privilege Escalation Vulnerability
References:
References:
- eZ Publish Homepage (eZ Publish)
- EZSA-2008-003: Insufficient form handling made privilege escalation possible (eZ Publish)