vendor:
ArticleFR
by:
High-Tech Bridge Security Research Lab
9,8
CVSS
CRITICAL
Improper Access Control
284
CWE
Product Name: ArticleFR
Affected Version From: 11.06.2014
Affected Version To: 11.06.2014
Patch Exists: YES
Related CWE: CVE-2014-4170
CPE: articlefr
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2014
Improper Access Control in ArticleFR
The vulnerability exists due to insufficient access restrictions when accessing the "/data.php" script. A remote attacker can send a specially crafted HTTP GET request to vulnerable script and execute arbitrary UPDATE SQL commands in application’s database. Successful exploitation of the vulnerability allows modification of arbitrary database record. A remote attacker can modify or delete information stored in database and gain complete control over the application.
Mitigation:
The vulnerability was fixed in ArticleFR version 11.07.2014.