PT-2007-6728 · Agtc · Agtc-Membership System
Publicado
2007-10-31
·
Atualizado
2018-10-15
·
CVE-2007-5752
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AGTC-Membership System version 1.1a
Description
The issue concerns the adduser.php file, which does not require authentication. This allows remote attackers to create accounts by modifying the form. For example, an attacker can create an account with admin privileges, specifically userlevel 4.
Recommendations
For AGTC-Membership System version 1.1a, consider implementing authentication requirements for the adduser.php file to prevent unauthorized account creation. As a temporary workaround, restrict access to the adduser.php file until a proper authentication mechanism is in place.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Agtc-Membership System