PT-2007-1353 · Smartsitecms · Smartsitecms

Paulino Calderon

·

Publicado

2007-02-27

·

Atualizado

2017-07-29

·

CVE-2006-7074

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SmartSiteCMS version 1.0
Description The issue allows remote attackers to bypass authentication and gain administrator privileges. This is achieved by setting the userName cookie in the admin.php file.
Recommendations For SmartSiteCMS version 1.0, consider restricting access to the admin.php file until a patch is available. As a temporary workaround, avoid using the userName cookie in the affected file to minimize the risk of exploitation.

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-7074

Produtos afetados

Smartsitecms