PT-2004-3039 · Baal · Baal Smart Forms

Published

2004-12-31

·

Updated

2024-01-25

·

CVE-2004-2144

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Baal Smart Forms versions prior to 3.2
Description The issue allows remote attackers to bypass authentication and obtain system access via a direct request to "regadmin.php".
Recommendations For versions prior to 3.2, update to version 3.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "regadmin.php" file until the update is applied.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2004-2144

Affected Products

Baal Smart Forms