Korean
<< Back
VID 21937
Severity 30
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The Siteman program, according to its version number, has an User Database Privilege Escalation vulnerability. SiteMan is a Content Management System (CMS) for Web site creation and site management. Siteman version 1.1.10 and earlier versions could allow a remote attacker to gain elevated database privileges. A remote attacker could send a specially-crafted HTTP POST request to the users.php script to add a user with administrative privileges or supply the docreate function with a specially-crafted line parameter to create a user account with administrator privileges.

* Note: This check solely relied on the version number of SiteMan on the remote Web server to assess this vulnerability, so this might be a false positive.

* References:
http://marc.theaimsgroup.com/?l=bugtraq&m=110643320814371&w=2
http://www.securitytracker.com/alerts/2005/Jan/1012951.html
http://archives.neohapsis.com/archives/bugtraq/2005-01/0239.html

* Platforms Affected:
Siteman SourceForge project, Siteman versions 1.1.10 and earlier
Any operating system Any version
Recommendation Upgrade to the latest version of Siteman (1.1.11 or later), available from the SourceForge.net Siteman Project Download Web site at http://sourceforge.net/projects/sitem
Related URL CVE-2005-0305 (CVE)
Related URL 12304,12558 (SecurityFocus)
Related URL 18998 (ISS)