Vulnerability CVE-2007-3191


Published: 2007-06-12   Modified: 2012-02-12

Description:
Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to obtain configuration information via a direct request to admin/adm/test.php, which calls the phpinfo function.

Type:

CWE-Other

Vendor: Jffnms
Product: Just for fun network management system 
Version: 0.8.3;

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.4/10
9.2/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
None

 References:
http://marc.info/?l=full-disclosure&m=118151087109711&w=2
http://www.debian.org/security/2007/dsa-1374
http://www.securityfocus.com/archive/1/471039/100/0/threaded
http://www.securityfocus.com/bid/24414

Related CVE
CVE-2007-3204
SQL injection vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.4-pre2 allows remote attackers to execute arbitrary SQL commands via the pass parameter. NOTE: this issue reportedly exists because of an initial incomple...
CVE-2007-3189
Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter.
CVE-2007-3190
Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass parameters.
CVE-2007-3192
admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.

Copyright 2019, cxsecurity.com

 

Back to Top