vendor:
Pre ADS Portal
by:
G4N0K
7.5
CVSS
HIGH
Admin BYpass, XSS
79, 352
CWE
Product Name: Pre ADS Portal
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Pre ADS Portal <= 2.0 Multiple Vulnerabilities
Pre ADS Portal is prone to multiple vulnerabilities, including an authentication bypass vulnerability and multiple cross-site scripting vulnerabilities. An attacker can exploit these issues to bypass authentication and execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to control how the site is rendered to the user; other attacks are also possible.
Mitigation:
Users should avoid following untrusted links and should never enter credentials after being redirected to a different website. Administrators should disable the affected script.