gBook Administrative Access Vulnerability
BID:6033
Info
gBook Administrative Access Vulnerability
| Bugtraq ID: | 6033 |
| Class: | Input Validation Error |
| CVE: |
CVE-2002-1560 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2002 12:00AM |
| Updated: | Jul 11 2009 06:06PM |
| Credit: | Discovery credited to Frog Man. |
| Vulnerable: |
gBook gBook 1.4 |
| Not Vulnerable: | |
Discussion
gBook Administrative Access Vulnerability
A vulnerability has been discovered in gBook v1.4.
It has been reported that it is possible for an unauthorized attacker to gain administrative access to gBook by passing a malicious request to a php script.
Exploiting this issue could allow unauthorized attackers to execute arbitrary administrative actions against the target guestbook, such as corrupt valid user supplied entries.
A vulnerability has been discovered in gBook v1.4.
It has been reported that it is possible for an unauthorized attacker to gain administrative access to gBook by passing a malicious request to a php script.
Exploiting this issue could allow unauthorized attackers to execute arbitrary administrative actions against the target guestbook, such as corrupt valid user supplied entries.
Exploit / POC
gBook Administrative Access Vulnerability
The following proof of concept has been supplied by Frog Man:
http://[Target]/gb/index.php?login=true
The following proof of concept has been supplied by Frog Man:
http://[Target]/gb/index.php?login=true
Solution / Fix
gBook Administrative Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
gBook Administrative Access Vulnerability
References:
References: