vendor:
Micro CMS
by:
StAkeR
7.5
CVSS
HIGH
Remote Exploit
N/A
CWE
Product Name: Micro CMS
Affected Version From: 2000.3.5
Affected Version To: 2000.3.5
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
Micro CMS <= 0.3.5 Remote (Add/Delete/Password Change) Exploit
This exploit allows an attacker to remotely add, delete, and change the password of an administrator on a vulnerable Micro CMS <= 0.3.5 system. The exploit requires the attacker to know the host, path, and the administrator's ID. The attacker can then use the exploit to delete the administrator, change the administrator's password, or add a new administrator.
Mitigation:
Upgrade to a version of Micro CMS that is not vulnerable to this exploit.