PT-2009-6268 · Telepark · Telepark.Wiki
Publicado
2009-11-27
·
Atualizado
2017-08-17
·
CVE-2009-4089
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
telepark.wiki versions 2.4.23 and earlier
Description
The issue allows remote attackers to bypass authorization. This can lead to the deletion of arbitrary pages via a modified
pageID parameter to "ajax/deletePage.php" or the deletion of arbitrary comments via a modified pageID parameter to "ajax/deleteComment.php".Recommendations
For telepark.wiki versions 2.4.23 and earlier, as a temporary workaround, consider restricting access to the "ajax/deletePage.php" and "ajax/deleteComment.php" endpoints until a patch is available. Avoid using the
pageID parameter in these affected endpoints until the issue is resolved.Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Telepark.Wiki