CVE-2009-1771 Information

Description

index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action which allows remote attackers to create or modify admin accounts via the (1) users[fullname] (2) users[email] (3) users[role_id] (4) users[username] and (5) users[password] parameters.

Reference

http://www.securityfocus.com/bid/35011 http://www.vupen.com/english/advisories/2009/1367 https://www.exploit-db.com/exploits/8714

Share on: