Website Baker 'framework/class.wb.php' Security Bypass Vulnerability
BID:38434
Info
Website Baker 'framework/class.wb.php' Security Bypass Vulnerability
| Bugtraq ID: | 38434 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2010 12:00AM |
| Updated: | Feb 26 2010 12:00AM |
| Credit: | The vendor credits Chio, Thorn, and Stefek |
| Vulnerable: |
Website Baker Website Baker 2.8 |
| Not Vulnerable: |
Website Baker Website Baker 2.8.2 |
Discussion
Website Baker 'framework/class.wb.php' Security Bypass Vulnerability
Website Baker is prone to a security-bypass vulnerability.
Attackers may exploit the issue to bypass certain security restrictions and perform unauthorized actions.
Website Baker 2.8.0 is vulnerable; other versions may also be affected.
Website Baker is prone to a security-bypass vulnerability.
Attackers may exploit the issue to bypass certain security restrictions and perform unauthorized actions.
Website Baker 2.8.0 is vulnerable; other versions may also be affected.
Exploit / POC
Website Baker 'framework/class.wb.php' Security Bypass Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
Website Baker 'framework/class.wb.php' Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Website Baker Website Baker 2.8
Solution:
Updates are available. Please see the references for more information.
Website Baker Website Baker 2.8
-
Website Baker WebsiteBaker_2.8.1.tar.gz
http://www.websitebaker2.org/modules/download_gallery/dlc.php?file=88& id=1266141493 -
Website Baker WebsiteBaker_2.8.1.zip
http://www.websitebaker2.org/modules/download_gallery/dlc.php?file=87& id=1266141495
References
Website Baker 'framework/class.wb.php' Security Bypass Vulnerability
References:
References:
- Website Baker Homepage (Website Baker)
- Website Baker Security Advisory: Security Patch for WB 2.8.0 available (Website Baker)