PT-2006-2229 · Jiro · Jiro'S Banner System

Published

2006-03-14

·

Updated

2018-10-18

·

CVE-2006-1213

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JiRo's Banner System Experience and Professional versions 1.0 and earlier
Description The issue allows remote attackers to bypass access restrictions and gain privileges by making a direct request to certain scripts in the files directory. For example, an attacker can use the addadmin.asp script to create a new administrator account, demonstrating the potential for unauthorized access and privilege escalation.
Recommendations For versions 1.0 and earlier, consider restricting access to the files directory and its scripts, such as addadmin.asp, to minimize the risk of exploitation. As a temporary workaround, limit the functionality of these scripts until a fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1213

Affected Products

Jiro'S Banner System