Exploit TTS Software Time Tracking Software 3.0 - 'edituser.php' Access Validation

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
27250
Проверка EDB
  1. Пройдено
Автор
ALIAKSANDR HARTSUYEU
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-0691
Дата публикации
2006-02-20
Код:
source: https://www.securityfocus.com/bid/16731/info

Time Tracking Software is prone to an access-validation vulnerability. This issue is due the application's failure to limit access to administrative sections of the application. 

An attacker can exploit this vulnerability to modify user data in the context of the application. This may result in a loss of confidentiality. The attacker may use this information in further attacks. 

This issue is reported to affect Time Tracking Software version 3.0; other versions may also be vulnerable.

http://www.example.com/timetracking/edituser.php? num=[userid]
 
Источник
www.exploit-db.com

Похожие темы