vendor:
CoffieNet CMS
by:
indoushka
8,8
CVSS
HIGH
By Pass Admin Vulnerability
287
CWE
Product Name: CoffieNet CMS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: a:coffienet:coffienet_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2009
CoffieNet CMs By Pass Admin Vulnerability
An attacker can bypass the authentication of the CoffieNet CMS by accessing the admin.php and img_upload.php files directly. This vulnerability affects Windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu).
Mitigation:
Ensure that authentication is enforced for all administrative functions and that access to the admin.php and img_upload.php files is restricted.