Max.Blog 'delete.php' Delete Post Authentication Bypass Vulnerability
BID:33368
Info
Max.Blog 'delete.php' Delete Post Authentication Bypass Vulnerability
| Bugtraq ID: | 33368 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2009 12:00AM |
| Updated: | Jan 26 2009 06:59PM |
| Credit: | SirGod |
| Vulnerable: |
Max.Blog Max.Blog 1.0.6 |
| Not Vulnerable: | |
Discussion
Max.Blog 'delete.php' Delete Post Authentication Bypass Vulnerability
Max.Blog is prone to an authentication-bypass vulnerability because it fails to properly enforce privilege requirements on some operations.
Successful exploits will allow attackers to delete arbitrary posts.
Max.Blog 1.0.6 is vulnerable; other versions may also be affected.
Max.Blog is prone to an authentication-bypass vulnerability because it fails to properly enforce privilege requirements on some operations.
Successful exploits will allow attackers to delete arbitrary posts.
Max.Blog 1.0.6 is vulnerable; other versions may also be affected.
Exploit / POC
Max.Blog 'delete.php' Delete Post Authentication Bypass Vulnerability
An attacker can exploit this issue using a web browser.
The following example exploit is available:
An attacker can exploit this issue using a web browser.
The following example exploit is available:
Solution / Fix
Max.Blog 'delete.php' Delete Post Authentication Bypass Vulnerability
Solution:
The vendor released a patch to address this issue. Please see the references for more information.
Max.Blog Max.Blog 1.0.6
Solution:
The vendor released a patch to address this issue. Please see the references for more information.
Max.Blog Max.Blog 1.0.6
-
Max.Blog security_fix.zip
http://www.mzbservices.com/useruploads/files/security_fix.zip
References
Max.Blog 'delete.php' Delete Post Authentication Bypass Vulnerability
References:
References:
- CRITICAL SECURITY ISSUE (Max.Blog)
- Max.Blog Homepage (mzbservices.com )