PT-2002-1970 · Voxel Dot Net · Voxel Dot Net Cbms

Published

2002-08-31

·

Updated

2008-09-05

·

CVE-2002-0961

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Voxel Dot Net CBMS versions 0.7 and earlier
Description: The issue allows remote attackers to perform unauthorized actions as other users. This can be achieved by exploiting vulnerabilities, such as possibly through a SQL injection attack, to conduct operations like deleting clients via the "dltclnt.php" endpoint.
Recommendations: For versions 0.7 and earlier, consider restricting access to the "dltclnt.php" endpoint until a fix is available. As a temporary workaround, limit the functionality of this endpoint to prevent unauthorized deletion of clients.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0961

Affected Products

Voxel Dot Net Cbms