PT-2005-3239 · Realnode · Realnode Emilda
Published
2005-07-19
·
Updated
2008-09-05
·
CVE-2005-2312
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Realnode Emilda versions 1.2.2 and earlier
Description:
The issue allows remote attackers to perform actions as other users. This is achieved by modifying the
user id parameter in the "management.php" endpoint.Recommendations:
For versions 1.2.2 and earlier, consider restricting access to the "management.php" endpoint until a fix is available. As a temporary workaround, avoid using the
user id parameter in the affected endpoint to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Realnode Emilda