PT-2006-7182 · Pronews · Pronews
Publicado
2006-12-15
·
Atualizado
2008-09-05
·
CVE-2006-6580
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ProNews version 1.5
Description
The issue concerns a lack of permission checks in the admin/change.php file, allowing remote attackers to modify news items without proper authorization. This could enable attackers to add or delete information within an item, potentially having other impacts.
Recommendations
For ProNews version 1.5, consider implementing proper access controls to restrict modifications to authorized users until a patch is available. As a temporary workaround, restrict access to the admin/change.php file to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Pronews