PT-2007-4866 · Vrnews · Vrnews

R4M!

·

Published

2007-07-06

·

Updated

2017-09-29

·

CVE-2007-3611

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions VRNews versions 1.1.1 and possibly other 1.x versions
Description The issue allows remote attackers to perform certain administrative actions without authentication. This can be achieved by sending a direct request with specific values in the act parameter, such as edit, add, config, or del.
Recommendations For VRNews version 1.1.1, consider restricting access to the admin.php file until a proper authentication mechanism is implemented. For other potentially affected 1.x versions, apply the same restriction to the admin.php file to prevent unauthorized administrative actions.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3611

Affected Products

Vrnews