vendor:
Ultimate PHP Board
by:
i2sec - Gi bum Hong
7.5
CVSS
HIGH
Broken Authentication and Session Management
287
CWE
Product Name: Ultimate PHP Board
Affected Version From: 2.2.2007
Affected Version To: 2.2.2007
Patch Exists: NO
Related CWE: N/A
CPE: a:textmb:ultimate_php_board:2.2.7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache 2.2.14, MySQL 5.1.39, PHP 5.2.12
2011
Ultimate PHP Board 2.2.7 “Broken Authentication and Session Management”
This vulnerability allows an attacker to delete another user's upload file by changing the request message to attacking file's post ID and file ID/name.
Mitigation:
Ensure that authentication and session management mechanisms are properly implemented and enforced.