PHPMyPub Unauthorized Administrative Access Vulnerability
BID:6645
Info
PHPMyPub Unauthorized Administrative Access Vulnerability
| Bugtraq ID: | 6645 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2003 12:00AM |
| Updated: | Jan 20 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
PHPMyPub PHPMyPub 1.2 .0 |
| Not Vulnerable: | |
Discussion
PHPMyPub Unauthorized Administrative Access Vulnerability
A problem with PHPMyPub may allow unauthorized users to obtain administrative access to a site hosting PHPMyPub.
The vulnerability exists due to inadequate checks performed by some administrative scripts. An attacker can exploit this vulnerability by creating a specifically named cookie with a non-zero value. This will allow an attacker to obtain administrative access to the site hosting PHPMyPub.
A problem with PHPMyPub may allow unauthorized users to obtain administrative access to a site hosting PHPMyPub.
The vulnerability exists due to inadequate checks performed by some administrative scripts. An attacker can exploit this vulnerability by creating a specifically named cookie with a non-zero value. This will allow an attacker to obtain administrative access to the site hosting PHPMyPub.
References
PHPMyPub Unauthorized Administrative Access Vulnerability
References:
References:
- PHPMyPub Home Page (PHPMyPub)
- PHPMyPub (PHP) ("Frog Man"
)