Newsscript Administrative Privilege Elevation Vulnerability
BID:7705
Info
Newsscript Administrative Privilege Elevation Vulnerability
| Bugtraq ID: | 7705 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2003 12:00AM |
| Updated: | May 27 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Peter Winter-Smith. |
| Vulnerable: |
Newsscript Newsscript 1.0 |
| Not Vulnerable: | |
Discussion
Newsscript Administrative Privilege Elevation Vulnerability
A vulnerability has been reported that could enable a member of the news system to create and access an administrative account. This is due to insufficient validation of data supplied to account editing input fields of Newsscript.
A vulnerability has been reported that could enable a member of the news system to create and access an administrative account. This is due to insufficient validation of data supplied to account editing input fields of Newsscript.
Exploit / POC
Newsscript Administrative Privilege Elevation Vulnerability
This may be exploited with a web browser. The member may add a database delimiter when changing their name in addition to a new privilege level, for example:
Peter<~>2
This may be exploited with a web browser. The member may add a database delimiter when changing their name in addition to a new privilege level, for example:
Peter<~>2
References
Newsscript Administrative Privilege Elevation Vulnerability
References:
References:
- Newsscript Homepage (Deathfragger)