PT-2007-1293 · Bloggit · Bloggit

Federico Fazzi

·

Publicado

2007-02-15

·

Atualizado

2018-10-16

·

CVE-2006-7014

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BloggIT versions 1.01 and earlier
Description The issue arises from improper user session establishment in the admin.php file, allowing remote attackers to gain privileges through a direct request.
Recommendations For BloggIT versions 1.01 and earlier, consider restricting access to the admin.php file until a proper fix is available. As a temporary workaround, ensure that all user sessions are properly validated and established to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-7014

Produtos afetados

Bloggit