PT-2007-6728 · Agtc · Agtc-Membership System

Published

2007-10-31

·

Updated

2018-10-15

·

CVE-2007-5752

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AGTC-Membership System version 1.1a
Description The issue concerns the adduser.php file, which does not require authentication. This allows remote attackers to create accounts by modifying the form. For example, an attacker can create an account with admin privileges, specifically userlevel 4.
Recommendations For AGTC-Membership System version 1.1a, consider implementing authentication requirements for the adduser.php file to prevent unauthorized account creation. As a temporary workaround, restrict access to the adduser.php file until a proper authentication mechanism is in place.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5752

Affected Products

Agtc-Membership System