vendor:
Orion-Blog
by:
UniquE-Key{UniquE-Cracker}
5.5
CVSS
MEDIUM
Privilege Escalation
264
CWE
Product Name: Orion-Blog
Affected Version From: Orion-Blog v2.0
Affected Version To: Orion-Blog v2.0
Patch Exists: NO
Related CWE:
CPE: a:orion-blog:orion-blog:2.0
Platforms Tested:
2007
Orion-Blog v2.0 Version Remote Privilege Escalation Exploit
This exploit allows for remote privilege escalation in Orion-Blog v2.0 Version. It takes advantage of a bug in the admin default.asp script. By submitting a specific form, an attacker can escalate their privileges.
Mitigation:
Update to a patched version of Orion-Blog v2.0 or apply the vendor's recommended security measures.