PT-2007-6728 · Agtc · Agtc-Membership System
Published
2007-10-31
·
Updated
2018-10-15
·
CVE-2007-5752
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AGTC-Membership System version 1.1a
Description
The issue concerns the adduser.php file, which does not require authentication. This allows remote attackers to create accounts by modifying the form. For example, an attacker can create an account with admin privileges, specifically userlevel 4.
Recommendations
For AGTC-Membership System version 1.1a, consider implementing authentication requirements for the adduser.php file to prevent unauthorized account creation. As a temporary workaround, restrict access to the adduser.php file until a proper authentication mechanism is in place.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Agtc-Membership System