PT-2008-6760 · Slimcms · Slimcms
Staker
·
Published
2008-12-24
·
Updated
2017-09-29
·
CVE-2008-5708
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SlimCMS version 1.0.0
Description
The issue allows remote attackers to create administrative users without requiring authentication. This can be achieved by utilizing the
newusername and newpassword parameters and setting the newisadmin parameter to 1 in the 'redirect.php' file.Recommendations
For SlimCMS version 1.0.0, consider restricting access to the 'redirect.php' file until a patch is available, or apply authentication requirements to this file to prevent unauthorized user creation.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Slimcms