PT-2007-4866 · Vrnews · Vrnews

R4M!

·

Publicado

2007-07-06

·

Atualizado

2017-09-29

·

CVE-2007-3611

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VRNews versions 1.1.1 and possibly other 1.x versions
Description The issue allows remote attackers to perform certain administrative actions without authentication. This can be achieved by sending a direct request with specific values in the act parameter, such as edit, add, config, or del.
Recommendations For VRNews version 1.1.1, consider restricting access to the admin.php file until a proper authentication mechanism is implemented. For other potentially affected 1.x versions, apply the same restriction to the admin.php file to prevent unauthorized administrative actions.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3611

Produtos afetados

Vrnews