vendor:
Nukedit
by:
r3dm0v3
7.5
CVSS
HIGH
Authentication Bypass
89
CWE
Product Name: Nukedit
Affected Version From: 4.9.x
Affected Version To: 4.9.x
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Nukedit 4.9.x Create Admin Exploit
This exploit allows an attacker to bypass authentication and create an admin account on Nukedit 4.9.x and prior versions. The exploit uses a SQL injection vulnerability in the login page to bypass authentication and then uses the useradmin.asp page to create an admin account with the username and password of the attacker's choice.
Mitigation:
No fix is available for this vulnerability.