P-News Administrative Account Creation Vulnerability
BID:7689
Info
P-News Administrative Account Creation Vulnerability
| Bugtraq ID: | 7689 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 24 2003 12:00AM |
| Updated: | May 24 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Peter Winter-Smith <[email protected]>. |
| Vulnerable: |
PpoPn P-News 1.16 |
| Not Vulnerable: | |
Discussion
P-News Administrative Account Creation Vulnerability
A vulnerability has been reported that could enable a P-News member to create and access an administrative account. This is due to insufficient validation of data supplied to account editing input fields of P-News.
This issue was reported in P-News 1.16. Other versions may also be affected.
A vulnerability has been reported that could enable a P-News member to create and access an administrative account. This is due to insufficient validation of data supplied to account editing input fields of P-News.
This issue was reported in P-News 1.16. Other versions may also be affected.
Exploit / POC
P-News Administrative Account Creation Vulnerability
This issue can be exploited with a web browser. The following input for the 'Name' field of the account editing form will create an administrative user named Peter:
Peter|-|21232f297a57a5a743894a0e4a801fc3|-|0|-|[email protected]|-||-|179ad45c6ce2cb97cf1029e212046e81|-|2|-|[email protected]|-|
This issue can be exploited with a web browser. The following input for the 'Name' field of the account editing form will create an administrative user named Peter:
Peter|-|21232f297a57a5a743894a0e4a801fc3|-|0|-|[email protected]|-||-|179ad45c6ce2cb97cf1029e212046e81|-|2|-|[email protected]|-|
Solution / Fix
P-News Administrative Account Creation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.