Umbraco CMS Administrative Pages Unauthorized Access Vulnerability
BID:34166
Info
Umbraco CMS Administrative Pages Unauthorized Access Vulnerability
| Bugtraq ID: | 34166 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2009 12:00AM |
| Updated: | Mar 18 2009 07:26PM |
| Credit: | Pratiksha Doshi |
| Vulnerable: |
Umbraco Umbraco CMS 3 |
| Not Vulnerable: |
Umbraco Umbraco CMS 4.7 |
Discussion
Umbraco CMS Administrative Pages Unauthorized Access Vulnerability
Umbraco CMS is prone to an access-validation vulnerability.
An attacker can exploit this issue to gain unauthorized access to unspecified administrative pages of the affected application. Successful attacks may aid the attacker in further attacks.
Umbraco CMS 3 is vulnerable; other versions may also be affected.
Umbraco CMS is prone to an access-validation vulnerability.
An attacker can exploit this issue to gain unauthorized access to unspecified administrative pages of the affected application. Successful attacks may aid the attacker in further attacks.
Umbraco CMS 3 is vulnerable; other versions may also be affected.
Exploit / POC
Umbraco CMS Administrative Pages Unauthorized Access Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
Umbraco CMS Administrative Pages Unauthorized Access Vulnerability
Solution:
Reports indicate this issue has been addressed in Umbraco CMS 4, but this has not been confirmed. Please contact the vendor for more information.
Solution:
Reports indicate this issue has been addressed in Umbraco CMS 4, but this has not been confirmed. Please contact the vendor for more information.
References
Umbraco CMS Administrative Pages Unauthorized Access Vulnerability
References:
References:
- Umbraco CMS Homepage (Umbraco)