PT-2004-2475 · Silent Storm · Silent Storm Portal

R00Tcr4Ck

·

Published

2004-12-31

·

Updated

2017-07-11

·

CVE-2004-1567

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Silent Storm Portal versions 2.1 through 2.2
Description The issue allows remote attackers to gain privileges. This is achieved by setting the mail parameter to 1, which is the value associated with an administrator.
Recommendations For Silent Storm Portal versions 2.1 through 2.2, consider restricting access to the profile.php page until a fix is available, and avoid using the mail parameter with the value of 1 to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1567

Affected Products

Silent Storm Portal