LinksCaffe 2.0/3.0 - Authentication Bypass

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1055827 漏洞类型
发布时间 2006-07-25 更新时间 2006-07-25
CVE编号 N/A CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/28442
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/19763/info

LinksCaffe is prone to an authentication-bypass vulnerability because of a lack of required authentication on the application's administrative script. An attacker can use administrative functions simply by knowing the script's name and location.

A successful exploit of this issue could allow an attacker to compromise the application, access or modify data, delete site content, or exploit vulnerabilities in the system or underlying database implementation. Other attacks are also possible.

Versions 2.0 and 3.0 are reported vulnerable; other versions may also be affected.

http://www.example.com/[path_to_linksCaffe]/Admin/admin1953.php