PHPRecipeBook Data Modification Vulnerability
BID:6819
Info
PHPRecipeBook Data Modification Vulnerability
| Bugtraq ID: | 6819 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2003 12:00AM |
| Updated: | Feb 06 2003 12:00AM |
| Credit: | This vulnerability was announced in the project changelog. |
| Vulnerable: |
PHPRecipeBook PHPRecipeBook 1.30 a PHPRecipeBook PHPRecipeBook 1.30 PHPRecipeBook PHPRecipeBook 1.27 a PHPRecipeBook PHPRecipeBook 1.27 PHPRecipeBook PHPRecipeBook 1.26 a PHPRecipeBook PHPRecipeBook 1.26 PHPRecipeBook PHPRecipeBook 1.25 PHPRecipeBook PHPRecipeBook 1.24 |
| Not Vulnerable: |
PHPRecipeBook PHPRecipeBook 1.31 |
Discussion
PHPRecipeBook Data Modification Vulnerability
PHPRecipeBook does not properly verify if a user is able to edit another user's recipes. This could allow any authenticated user to edit another user's recipes regardless of their privileges.
PHPRecipeBook does not properly verify if a user is able to edit another user's recipes. This could allow any authenticated user to edit another user's recipes regardless of their privileges.
Exploit / POC
PHPRecipeBook Data Modification Vulnerability
There is no exploit code required.
There is no exploit code required.