PT-2002-1970 · Voxel Dot Net · Voxel Dot Net Cbms
Published
2002-08-31
·
Updated
2008-09-05
·
CVE-2002-0961
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Voxel Dot Net CBMS versions 0.7 and earlier
Description:
The issue allows remote attackers to perform unauthorized actions as other users. This can be achieved by exploiting vulnerabilities, such as possibly through a SQL injection attack, to conduct operations like deleting clients via the "dltclnt.php" endpoint.
Recommendations:
For versions 0.7 and earlier, consider restricting access to the "dltclnt.php" endpoint until a fix is available. As a temporary workaround, limit the functionality of this endpoint to prevent unauthorized deletion of clients.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Voxel Dot Net Cbms