PT-2008-1890 · Unknown · Uploadscript
Dj7Xpl
·
Published
2008-01-12
·
Updated
2017-09-29
·
CVE-2008-0246
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
UploadScript version 1.0
Description
The issue allows remote attackers to gain administrator privileges due to a lack of original password verification when changing to a new password. This is achieved via the
pass parameter in a 'nopass' (Set Password) action.Recommendations
For UploadScript version 1.0, consider disabling the password change functionality until a patch is available to enforce original password checks before allowing changes to a new password. Restrict access to the admin.php script to minimize the risk of exploitation. Avoid using the
pass parameter in the 'nopass' action for the time being.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uploadscript