planetNews Grants Administrative Access to Remote Users
|
|
SecurityTracker Alert ID: 1016385
|
|
SecurityTracker URL: http://securitytracker.com/id?1016385
|
|
CVE Reference: CVE-2006-3553
(Links to External Site)
|
|
OSVDB Reference: 27624
(Links to External Site)
|
Updated: Aug 4 2006
|
Original Entry Date: Jun 26 2006
|
Impact: User access via network
|
Exploit Included: Yes
|
Description: A vulnerability was reported in planetNews. A remote user can gain administrative access on the target system.
A remote user can directly access the 'admin/planetnews.php' script to add or modify news items or upload arbitrary code.
AlpEren and tugr@ discovered this vulnerability.
|
Impact: A remote user can gain administrative privileges on the target application.
|
Solution: No solution was available at the time of this entry.
|
Vendor URL: www.planetc.de/download/planetnews/planetnews.html (Links to External Site)
|
Cause: Access control error
|
Underlying OS: Linux (Any), UNIX (Any), Windows (Any)
|
Reported By: alp_eren@ayyildiz.org
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|