Beanwebb Guestbook Unauthorized Administrative Access Vulnerability
BID:7232
Info
Beanwebb Guestbook Unauthorized Administrative Access Vulnerability
| Bugtraq ID: | 7232 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 29 2003 12:00AM |
| Updated: | Mar 29 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "euronymous" <[email protected]>. |
| Vulnerable: |
Beanwebb Guestbook 1.0 |
| Not Vulnerable: | |
Discussion
Beanwebb Guestbook Unauthorized Administrative Access Vulnerability
A vulnerability has been reported for Guestbook that may allow remote attackers to obtain unauthorized access to administrative functions.
The vulnerability is likely due to insufficient permissions on the 'admin.php' script file.
A vulnerability has been reported for Guestbook that may allow remote attackers to obtain unauthorized access to administrative functions.
The vulnerability is likely due to insufficient permissions on the 'admin.php' script file.
Exploit / POC
Beanwebb Guestbook Unauthorized Administrative Access Vulnerability
The following proof of concept was provided:
http://hostname/guestbook/admin.php
The following proof of concept was provided:
http://hostname/guestbook/admin.php
References
Beanwebb Guestbook Unauthorized Administrative Access Vulnerability
References:
References:
- Beanwebb (Beanwebb)
- Beanwebb Guestbook v1.0 vulnerabilities ("euronymous"
)