Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

James Gray

#37278of 53,635
7.5Total CVSS
Vulnerabilities · 1
PT-2006-7372
7.5
2006-12-27
Fishyshoop · Fishyshoop · CVE-2006-6773
Name of the Vulnerable Software and Affected Versions: Fishyshoop version 0.930 beta Description: The issue allows remote attackers to create arbitrary administrative users. This is achieved by setting the `is admin` HTTP POST parameter to 1 in the `pages/register/register.php` file. Recommendations: For Fishyshoop version 0.930 beta, consider restricting access to the `pages/register/register.php` file until a patch is available, and avoid using the `is admin` parameter in this context to minimize the risk of exploitation.