Advertisement






WebspotBlogging Authentication Bypass Vulnerability

CVE Category Price Severity
Not available CWE-287 Not specified Not specified
Author Risk Exploitation Type Date
Not specified Not specified Not specified 2006-01-28
CVSS EPSS EPSSP
CVSS:4.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2006010043

Below is a copy:

New eVuln Advisory:
WebspotBlogging Authentication Bypass Vulnerability
http://evuln.com/vulns/41/summary.html

--------------------Summary----------------

Software: WebspotBlogging
Sowtware's Web Site: http://www.webspot.co.uk/
Versions: 3.0
Critical Level: Dangerous
Type: SQL Injection
Class: Remote
Status: Unpatched
Exploit: Available
Solution: Not Available
Discovered by: Aliaksandr Hartsuyeu (eVuln.com)
eVuln ID: EV0041

-----------------Description---------------
Vulnerable script:
login.php

Variable $_POST[username] isn't properly sanitized before being used in a SQL query. This can be used to make any SQL query by injecting arbitrary SQL code.

Condition: gpc_magic_quotes - off

Administrator has an ability to import themes using php code insertion from Admin Control Panel.

System access is possible.

--------------Exploit----------------------
Available at: http://evuln.com/vulns/41/exploit.html

--------------Solution---------------------
No Patch available.

--------------Credit-----------------------
Discovered by: Aliaksandr Hartsuyeu (eVuln.com)

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum