PHP-Coolfile Unauthorized Administrative Access Vulnerability
BID:9018
Info
PHP-Coolfile Unauthorized Administrative Access Vulnerability
| Bugtraq ID: | 9018 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2003 12:00AM |
| Updated: | Nov 11 2003 12:00AM |
| Credit: | Credited to <[email protected]>. |
| Vulnerable: |
PHP-Coolfile PHP-Coolfile 1.4 |
| Not Vulnerable: | |
Discussion
PHP-Coolfile Unauthorized Administrative Access Vulnerability
PHP-Coolfile allows unauthorized administrative access due to an error in the way access is evaluated in the action.php file. This could allow a remote user to obtain the administrative username and password for the site.
PHP-Coolfile allows unauthorized administrative access due to an error in the way access is evaluated in the action.php file. This could allow a remote user to obtain the administrative username and password for the site.
Exploit / POC
PHP-Coolfile Unauthorized Administrative Access Vulnerability
The following proof of concept was supplied:
www.site.com/php-coolfile/action.php?action=edit&file=config.php
The following proof of concept was supplied:
www.site.com/php-coolfile/action.php?action=edit&file=config.php
Solution / Fix
PHP-Coolfile Unauthorized Administrative Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHP-Coolfile Unauthorized Administrative Access Vulnerability
References:
References: