Vulnerability CVE-2007-3494


Published: 2007-06-29   Modified: 2012-02-12

Description:
Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, which allows remote authenticated users to (1) read the entire database by accessing the database backup plugin via a devtools/templates/newdump_backend.html argument in the template parameter to interna/plugin.php, (2) create plugins, (3) remove plugins, (4) enable debug mode, and have other unspecified impact.

See advisories in our WLB2 database:
Topic
Author
Date
High
Papoo CMS 3.6 - Access Restriction Bypass
Nico Leidecker
03.07.2007

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:S/C:C/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.8/10
6.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
None
None
Affected software
Papoo -> Papoo 

 References:
http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/064171.html
http://securityreason.com/securityalert/2853
http://www.papoo.de/index/menuid/204/reporeid/215
http://www.securityfocus.com/archive/1/472213/100/0/threaded
http://www.securityfocus.com/bid/24634
https://exchange.xforce.ibmcloud.com/vulnerabilities/35032

Copyright 2024, cxsecurity.com

 

Back to Top