LinksCaffe no checker at admin

2006.09.02
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-Other


CVSS Base Score: 7.5/10
Impact Subscore: 6.4/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Partial
Integrity impact: Partial
Availability impact: Partial

Gonafish.com LinksCaffe 3.0 is free link indexing directory, we found that the file admin1953.php can be accessed directly to get full administration rights without password and username. Proof of exploit: http://www.example.com/[path_to_linksCaffe]/Admin/admin1953.php Or the images of mirror http://vietnamsecurity.googlepages.com/1.JPG http://vietnamsecurity.googlepages.com/2.JPG http://vietnamsecurity.googlepages.com/3.JPG Affected LinksCaffe 2.0, 3.0, Pro no test Fix : Easy to fix, just put checker to the file HoangYenXinhDep Vietnam Security Team http://www.vnsecurity.com


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top