PT-2012-2068 · Gr Board · Gboard

Publicado

2012-05-24

·

Atualizado

2024-02-14

·

CVE-2011-5090

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions GR Board (aka grboard) version 1.8.6.5 Community Edition
Description The issue allows remote attackers to modify or delete data without requiring authentication for certain database actions. This can be achieved by sending a request to specific API endpoints, including "mod rewrite.php", "comment write ok.php", "poll/index.php", "update/index.php", "trackback.php", or an arbitrary "poll.php" script under the "theme/" directory.
Recommendations For GR Board (aka grboard) version 1.8.6.5 Community Edition, consider restricting access to the mentioned API endpoints, such as "mod rewrite.php", "comment write ok.php", "poll/index.php", "update/index.php", "trackback.php", and arbitrary "poll.php" scripts under "theme/", until a proper fix is available. Additionally, implementing proper authentication mechanisms for database actions can help mitigate the risk of unauthorized data modification or deletion.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-5090

Produtos afetados

Gboard