Previous articleBack to news listNext article |
Sponsored links |
Want to become one of our authors and see your work published on ALLSeek.iNFO ? |
| Bandsite Portal Software Authentication Flaw Lets Remote Users Add Administrators |
|---|
Categorie: Vulnerability Posted: 2003-09-15 by ReCall Views: 348 Source: Click here | Current Rating: Not rated
|
|
| Details |
|---|
Description: Nasser.M.Sh reported a vulnerability in Bandsite. A remote user can gain administrative access on the application.
It is reported that a remote user can submit a specially crafted POST request to the following URL to add a user account that will have administrator privileges on the application:
http://[target]/bandwebsite/admin.php?&Login=1§ion=admins
The vendor has reportedly been notified without response.
Impact: A remote user can add administrative user accounts.
Solution: No solution was available at the time of this entry. |
| Syndication |
|---|
Permalink Email this
The URI to TrackBack this entry is: http://allseek.info/news/trackback.php?id=430
|
| User comments (post your comments ) |
|---|
Only registerd members can post comments and articles |
|
Previous articleBack to news listNext article |