PT-2008-4462 · Unknown · Rss-Aggregator
Sylvain Thual
·
Published
2008-07-07
·
Updated
2018-10-11
·
CVE-2008-3033
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RSS-aggregator version 1.0
Description
The issue allows remote attackers to access admin functions without requiring administrative authentication for the admin/fonctions/ directory. This can be exploited through specific requests, such as (1) an IdFlux request to "supprimer flux.php" and (2) a TpsRafraich request to "modifier tps rafraich.php", potentially leading to unspecified other impact.
Recommendations
For RSS-aggregator version 1.0, consider implementing proper authentication mechanisms for the admin/fonctions/ directory to restrict unauthorized access. As a temporary workaround, restrict access to the "supprimer flux.php" and "modifier tps rafraich.php" files until a proper fix is applied.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rss-Aggregator