PT-2007-2250 · Les News · Les News
Published
2007-02-07
·
Updated
2018-10-16
·
CVE-2007-0806
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Les News version 2.2
Description
The issue allows remote attackers to bypass authentication and gain administrative access. This can be achieved by making a direct request for the
adminews/index fr.php3 endpoint, and possibly the adminews index documents for other localizations.Recommendations
For Les News version 2.2, consider restricting access to the
adminews/index fr.php3 endpoint and other potentially vulnerable adminews index documents until a patch is available. As a temporary workaround, limit administrative access to trusted users and networks to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Les News