vendor:
Article Management System
by:
indoushka
6,5
CVSS
MEDIUM
Reinstall Vulnerability
264
CWE
Product Name: Article Management System
Affected Version From: 2.1.2
Affected Version To: 2.1.2
Patch Exists: NO
Related CWE: N/A
CPE: articlems:article_management_system
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2009
(ArticleMS) Article Management System 2.1.2 Reinstall Vulnerability
A vulnerability exists in Article Management System 2.1.2 which allows an attacker to reinstall the application by accessing the install/index.php?step=3 page. The attacker can then access the admin page at http://127.0.0.1/articlems_2_1_2/admin/.
Mitigation:
Ensure that the application is not exposed to the public internet and that access to the install/index.php page is restricted.