vendor:
Cahier de texte
by:
DarkFig
7,5
CVSS
HIGH
Bypass general access restriction
None
CWE
Product Name: Cahier de texte
Affected Version From: V2.2
Affected Version To: V2.2
Patch Exists: NO
Related CWE: None
CPE: None
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Cahier de texte V2.2 Exploit
This exploit allows an attacker to bypass the general access restriction of Cahier de texte V2.2 by exploiting a vulnerability in the code. The vulnerable code is a PHP script that checks if the user is an administrator, and if not, redirects them to the index page. The exploit uses a socket connection to send a request to the server, bypassing the access restriction.
Mitigation:
Ensure that the access restriction code is secure and cannot be bypassed.