Vulnerabilities > CVE-2002-0096 - Unspecified vulnerability in Geeklog 1.3

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
geeklog
nessus

Summary

The installation of Geeklog 1.3 creates an extra group_assignments record which is not properly deleted, which causes the first newly created user to be added to the GroupAdmin and UserAdmin groups, which could provide that user with administrative privileges that were not intended.

Vulnerable Configurations

Part Description Count
Application
Geeklog
1

Nessus

NASL familyCGI abuses
NASL idGEEKLOG_ADMIN_ACCESS.NASL
descriptionThe remote server is running a version of Geeklog affected by various vulnerabilities, including SQL injection, arbitrary file upload, privilege escalation, etc.
last seen2020-06-01
modified2020-06-02
plugin id11670
published2003-05-29
reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11670
titleGeeklog <= 1.3.7sr1 Multiple Vulnerabilities (SQLi, XSS, Priv Esc)