PT-2008-1890 · Unknown · Uploadscript

Dj7Xpl

·

Publicado

2008-01-12

·

Atualizado

2017-09-29

·

CVE-2008-0246

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions UploadScript version 1.0
Description The issue allows remote attackers to gain administrator privileges due to a lack of original password verification when changing to a new password. This is achieved via the pass parameter in a 'nopass' (Set Password) action.
Recommendations For UploadScript version 1.0, consider disabling the password change functionality until a patch is available to enforce original password checks before allowing changes to a new password. Restrict access to the admin.php script to minimize the risk of exploitation. Avoid using the pass parameter in the 'nopass' action for the time being.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0246

Produtos afetados

Uploadscript