PT-2007-1293 · Bloggit · Bloggit

Federico Fazzi

·

Published

2007-02-15

·

Updated

2018-10-16

·

CVE-2006-7014

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BloggIT versions 1.01 and earlier
Description The issue arises from improper user session establishment in the admin.php file, allowing remote attackers to gain privileges through a direct request.
Recommendations For BloggIT versions 1.01 and earlier, consider restricting access to the admin.php file until a proper fix is available. As a temporary workaround, ensure that all user sessions are properly validated and established to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7014

Affected Products

Bloggit