FusionPHP Fusion News管理员命令执行漏洞

FusionPHP Fusion News管理员命令执行漏洞

漏洞ID 1108092 漏洞类型 访问验证错误
发布时间 2004-07-30 更新时间 2005-10-20
图片[1]-FusionPHP Fusion News管理员命令执行漏洞-安全小百科CVE编号 CVE-2004-1703
图片[2]-FusionPHP Fusion News管理员命令执行漏洞-安全小百科CNNVD-ID CNNVD-200407-100
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/24341
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200407-100
|漏洞详情
FusionNews3.6.1版本存在漏洞。远程攻击者在管理员登陆时借助一个评论增加用户账号,该评论包含调用注册行为index.php的imgbbcode标签。该漏洞在管理员的浏览器加载带有inm标签页面时执行。
|漏洞EXP
source: http://www.securityfocus.com/bid/10836/info

It is reported that Fusion News is affected by an administrator command execution vulnerability. This issue is due to a failure of the application to properly validate access to administrative commands.

This issue permits a remote attacker to create a malicious URI link or embed a malicious URI between bbCode image tags, which includes hostile HTML and script code. If an unsuspecting forum administrator activates this URI, the attacker-supplied command would be carried out with the administrator's privileges. This occurs in the security context of the affected web site and would cause various administrator actions to be taken.

Version 3.6.1 and prior are reported to be affected by this vulnerability.

http://www.example.com/news/index.php?id=signup&username=example&[email protected]&password=password&icon=&le=3&timeoffset=1
|参考资料

来源:XF
名称:fusion-news-add-account(16853)
链接:http://xforce.iss.net/xforce/xfdb/16853
来源:BID
名称:10836
链接:http://www.securityfocus.com/bid/10836
来源:SECTRACK
名称:1010829
链接:http://securitytracker.com/id?1010829
来源:BUGTRAQ
名称:20040729FusionNewsYetAnotherUnauthorizedAccountAdditionVulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m;=109122824523226&w;=2

相关推荐: GeoHttpServer认证绕过漏洞

GeoHttpServer认证绕过漏洞 漏洞ID 1200584 漏洞类型 未知 发布时间 2004-12-31 更新时间 2004-12-31 CVE编号 CVE-2004-2100 CNNVD-ID CNNVD-200412-617 漏洞平台 N/A CV…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享