vendor:
Traq
by:
EgiX and TecR0c
N/A
CVSS
N/A
Authentication Bypass
N/A
CWE
Product Name: Traq
Affected Version From: 2
Affected Version To: 2.3
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2011
Traq <= 2.3 Authentication Bypass / Remote Code Execution Exploit
This module exploits an arbitrary command execution vulnerability in Traq 2.0 to 2.3. It's in the admincp/common.php script. This function is called in each script located into /admicp/ directory to make sure the user has admin rights, but this is a broken authorization schema due to the header() function doesn't stop the execution flow. This can be exploited by malicious users to execute admin functionality resulting for e.g. in execution of arbitrary PHP code leveraging of plugins.php functionality.
Mitigation:
N/A