Basic PHP Events Lister 2 Multiple Administrative Scripts Authentication Bypass Vulnerabilities
BID:36198
Info
Basic PHP Events Lister 2 Multiple Administrative Scripts Authentication Bypass Vulnerabilities
| Bugtraq ID: | 36198 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 31 2009 12:00AM |
| Updated: | Sep 01 2009 03:32PM |
| Credit: | Mr.SeCreT |
| Vulnerable: |
Mevin Productions Basic PHP Events Lister 2.0 |
| Not Vulnerable: | |
Discussion
Basic PHP Events Lister 2 Multiple Administrative Scripts Authentication Bypass Vulnerabilities
Basic PHP Events Lister 2 is prone to multiple authentication-bypass vulnerabilities because it fails to perform adequate authentication checks.
An attacker can exploit these issues to gain unauthorized access to the application and create administrative users or modify administrative passwords. This may lead to further attacks.
Basic PHP Events Lister 2.0 is vulnerable; other versions may also be affected.
Basic PHP Events Lister 2 is prone to multiple authentication-bypass vulnerabilities because it fails to perform adequate authentication checks.
An attacker can exploit these issues to gain unauthorized access to the application and create administrative users or modify administrative passwords. This may lead to further attacks.
Basic PHP Events Lister 2.0 is vulnerable; other versions may also be affected.
Exploit / POC
Basic PHP Events Lister 2 Multiple Administrative Scripts Authentication Bypass Vulnerabilities
An attacker can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/ [Path] /admin/reset.php
http://www.example.com/ [Path] /admin/user_add.php
An attacker can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/ [Path] /admin/reset.php
http://www.example.com/ [Path] /admin/user_add.php
Solution / Fix
Basic PHP Events Lister 2 Multiple Administrative Scripts Authentication Bypass Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Basic PHP Events Lister 2 Multiple Administrative Scripts Authentication Bypass Vulnerabilities
References:
References:
- Basic PHP Events Lister Homepage (Mevin Productions)