vendor:
LinksCaffe
by:
SecurityFocus
7.5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: LinksCaffe
Affected Version From: 2
Affected Version To: 3
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
LinksCaffe Authentication Bypass Vulnerability
LinksCaffe is prone to an authentication-bypass vulnerability because of a lack of required authentication on the application's administrative script. An attacker can use administrative functions simply by knowing the script's name and location. A successful exploit of this issue could allow an attacker to compromise the application, access or modify data, delete site content, or exploit vulnerabilities in the system or underlying database implementation. Other attacks are also possible.
Mitigation:
Ensure that authentication is required for all administrative functions.