Vulnerabilities > CVE-2002-0096 - Unspecified vulnerability in Geeklog 1.3

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
geeklog
nessus

Summary

The installation of Geeklog 1.3 creates an extra group_assignments record which is not properly deleted, which causes the first newly created user to be added to the GroupAdmin and UserAdmin groups, which could provide that user with administrative privileges that were not intended.

Vulnerable Configurations

Part Description Count
Application
Geeklog
1

Nessus

NASL familyCGI abuses
NASL idGEEKLOG_ADMIN_ACCESS.NASL
descriptionThe remote server is running a version of Geeklog affected by various vulnerabilities, including SQL injection, arbitrary file upload, privilege escalation, etc.
last seen2020-06-01
modified2020-06-02
plugin id11670
published2003-05-29
reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11670
titleGeeklog <= 1.3.7sr1 Multiple Vulnerabilities (SQLi, XSS, Priv Esc)