PT-2007-2250 · Les News · Les News
Publicado
2007-02-07
·
Atualizado
2018-10-16
·
CVE-2007-0806
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Les News version 2.2
Description
The issue allows remote attackers to bypass authentication and gain administrative access. This can be achieved by making a direct request for the
adminews/index fr.php3 endpoint, and possibly the adminews index documents for other localizations.Recommendations
For Les News version 2.2, consider restricting access to the
adminews/index fr.php3 endpoint and other potentially vulnerable adminews index documents until a patch is available. As a temporary workaround, limit administrative access to trusted users and networks to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Les News