PT-2006-7182 · Pronews · Pronews

Publicado

2006-12-15

·

Atualizado

2008-09-05

·

CVE-2006-6580

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions ProNews version 1.5
Description The issue concerns a lack of permission checks in the admin/change.php file, allowing remote attackers to modify news items without proper authorization. This could enable attackers to add or delete information within an item, potentially having other impacts.
Recommendations For ProNews version 1.5, consider implementing proper access controls to restrict modifications to authorized users until a patch is available. As a temporary workaround, restrict access to the admin/change.php file to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6580

Produtos afetados

Pronews