vendor:
Net Portal Dynamic System
by:
DarkFig
8,8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Net Portal Dynamic System
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: No
Related CWE: None
CPE: None
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
Unknown
Register multiple users for Denial of Service
NPDS (Net Portal Dynamic System) is a French(and now English !) GNU dynamic portal. The vulnerability allows an attacker to register multiple users for Denial of Service. The exploit works on the last version (5.0, tested) and probably prior versions. The exploit includes a malicious file for DDoS attack. The website can also be vulnerable if it sends passwords to the email, as it adds an email in the database.
Mitigation:
The website should be configured to prevent multiple user registrations. A visual confirmation should be added to the website to prevent malicious registrations.