PT-2005-4873 · Efiction · Efiction
Rgod
·
Published
2005-12-11
·
Updated
2008-09-05
·
CVE-2005-4174
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
eFiction versions 1.0 through 2.0
Description
The issue might allow remote attackers to conduct unauthorized operations. This can be achieved by directly accessing certain scripts, specifically "install.php" or "upgrade.php". It is unclear whether this is due to a vulnerability in eFiction itself or the result of incorrect system administration practices.
Recommendations
For versions 1.0 through 2.0, consider removing or restricting access to the "install.php" and "upgrade.php" scripts to prevent unauthorized operations. As a temporary workaround, restrict access to these scripts until it is determined whether the issue is due to a vulnerability in eFiction or incorrect system administration practices.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Efiction