PT-2008-5533 · Rianxosencabos · Rianxosencabos Cms

Cwh Underground

·

Publicado

2008-09-25

·

Atualizado

2017-09-29

·

CVE-2008-4245

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Rianxosencabos CMS version 0.9
Description: The issue concerns the Admin Control Panel, which does not require administrator privileges. This allows remote authenticated users to perform various administrative actions, including changing a user's privileges, deleting a user account, or other unspecified actions. These actions can be performed via vectors involving an admin lista action to the default URI, possibly related to the useradmin.php file.
Recommendations: For Rianxosencabos CMS version 0.9, consider restricting access to the Admin Control Panel to only authorized administrators until a fix is available. As a temporary workaround, limit the use of the admin lista action and access to the default URI to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4245

Produtos afetados

Rianxosencabos Cms