PT-2002-1356 · Site News · Site News

Publicado

2002-05-03

·

Atualizado

2017-07-11

·

CVE-2002-0286

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SiteNews versions 0.10 through 0.11
Description The issue allows remote attackers to gain privileges and add users by exploiting the GetPassword function in function.php. This is done by providing a non-existent user name and the MD5 checksum for an empty password to the add user.php endpoint, causing the GetPassword function to produce and compare a blank password for the non-existent user.
Recommendations For SiteNews versions 0.10 through 0.11, as a temporary workaround, consider disabling the GetPassword function until a patch is available. Restrict access to the add user.php endpoint to minimize the risk of exploitation. Avoid using the add user.php endpoint with non-existent user names until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0286

Produtos afetados

Site News