VID |
21937 |
Severity |
30 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The Siteman program, according to its version number, has an User Database Privilege Escalation vulnerability. SiteMan is a Content Management System (CMS) for Web site creation and site management. Siteman version 1.1.10 and earlier versions could allow a remote attacker to gain elevated database privileges. A remote attacker could send a specially-crafted HTTP POST request to the users.php script to add a user with administrative privileges or supply the docreate function with a specially-crafted line parameter to create a user account with administrator privileges.
* Note: This check solely relied on the version number of SiteMan on the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://marc.theaimsgroup.com/?l=bugtraq&m=110643320814371&w=2 http://www.securitytracker.com/alerts/2005/Jan/1012951.html http://archives.neohapsis.com/archives/bugtraq/2005-01/0239.html
* Platforms Affected: Siteman SourceForge project, Siteman versions 1.1.10 and earlier Any operating system Any version |
Recommendation |
Upgrade to the latest version of Siteman (1.1.11 or later), available from the SourceForge.net Siteman Project Download Web site at http://sourceforge.net/projects/sitem |
Related URL |
CVE-2005-0305 (CVE) |
Related URL |
12304,12558 (SecurityFocus) |
Related URL |
18998 (ISS) |
|