Py-Membres Secure.PHP Unauthorized Access Vulnerability
BID:8499
Info
Py-Membres Secure.PHP Unauthorized Access Vulnerability
| Bugtraq ID: | 8499 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 26 2003 12:00AM |
| Updated: | Aug 26 2003 12:00AM |
| Credit: | The disclosure of this issue has been credited to Frog Man <[email protected]>. |
| Vulnerable: |
Py-Membres Py-Membres 4.2 Py-Membres Py-Membres 4.1 Py-Membres Py-Membres 4.0 |
| Not Vulnerable: | |
Discussion
Py-Membres Secure.PHP Unauthorized Access Vulnerability
A vulnerability has been reported for Py-Membres that allows remote attackers to obtain administrative privileges on vulnerable installations.
Reportedly, Py-Membres does not fully check some URI parameters. Thus it is possible for an attacker to manipulate URI parameters and log into the system as an administrative user without the need for passwords.
A vulnerability has been reported for Py-Membres that allows remote attackers to obtain administrative privileges on vulnerable installations.
Reportedly, Py-Membres does not fully check some URI parameters. Thus it is possible for an attacker to manipulate URI parameters and log into the system as an administrative user without the need for passwords.
Exploit / POC
Py-Membres Secure.PHP Unauthorized Access Vulnerability
The following proof of concept was provided:
http://www.example.com/admin/admin.php?adminpy=1
The following proof of concept was provided:
http://www.example.com/admin/admin.php?adminpy=1