vendor:
Poster.version:two
by:
SecurityFocus
7.5
CVSS
HIGH
Access Control Vulnerability
264
CWE
Product Name: Poster.version:two
Affected Version From: 2
Affected Version To: 2
Patch Exists: YES
Related CWE: N/A
CPE: poster:two
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
Poster.version:two Vulnerability
The vulnerability occurs due to the application failing to lock the 'setup' variable after initialization. As a result, an attacker may access this variable to add additional adminstrator users to the forum. This may effectively allow for the theft or modification of sensitive information.
Mitigation:
Ensure that the 'setup' variable is locked after initialization.