vendor:
C.P.Sub
by:
Chako
7,5
CVSS
HIGH
Improper Authentication and Misconfiguration
287, 200
CWE
Product Name: C.P.Sub
Affected Version From: v4.5
Affected Version To: v4.5
Patch Exists: YES
Related CWE: N/A
CPE: a:cooltey:c.p.sub
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2013
C.P.Sub <= v4.5 Misconfiguration and Improper Authentication
C.P.Sub <= v4.5 use 'user_com=' parameter to identify if the user has admin privilege. Therefore an attacker could simply change the value for 'user_com=' parameter to gain admin privilege. There are some default accounts for C.P.Sub <= v4.5 that allows an attacker to access back-end management page. It could lead to further attack.
Mitigation:
Ensure that authentication is properly implemented and that default accounts are not used.