NewsPro 1.01 Unauthenticated Administrator Vulnerability
BID:4672
Info
NewsPro 1.01 Unauthenticated Administrator Vulnerability
| Bugtraq ID: | 4672 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-1734 |
| Remote: | Yes |
| Local: | No |
| Published: | May 04 2002 12:00AM |
| Updated: | Jan 31 2019 10:00PM |
| Credit: | Posted to BugTraq on May 5, 2002 by frog frog <[email protected]> |
| Vulnerable: |
ASPBin NewsPro 1.0 1 |
| Not Vulnerable: | |
Discussion
NewsPro 1.01 Unauthenticated Administrator Vulnerability
NewsPro 1.01 contains a weak authentication mechanism that allows administrative access to be gained. This is done by constructing a cookie containing "logged,true".
NewsPro 1.01 contains a weak authentication mechanism that allows administrative access to be gained. This is done by constructing a cookie containing "logged,true".
Exploit / POC
NewsPro 1.01 Unauthenticated Administrator Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
NewsPro 1.01 Unauthenticated Administrator Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.