Vulnerabilities > CVE-2005-0305 - Privilege Escalation vulnerability in Siteman User Database
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
CRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges via the line parameter in a docreate operation.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Exploit-Db
description Siteman 1.1 User Database Privilege Escalation Vulnerability (1). CVE-2005-0305. Webapps exploit for php platform id EDB-ID:25052 last seen 2016-02-03 modified 2005-01-19 published 2005-01-19 reporter Noam Rathaus source https://www.exploit-db.com/download/25052/ title Siteman 1.1 - User Database Privilege Escalation Vulnerability 1 description Siteman 1.1 User Database Privilege Escalation Vulnerability (2). CVE-2005-0305. Webapps exploit for php platform id EDB-ID:25053 last seen 2016-02-03 modified 2005-01-19 published 2005-01-19 reporter amironline452 source https://www.exploit-db.com/download/25053/ title Siteman 1.1 - User Database Privilege Escalation Vulnerability 2
Nessus
NASL family | CGI abuses |
NASL id | SITEMAN_USER_DB_PRIV_ESCALATION.NASL |
description | The remote host is running Siteman, a web-based content management system written in PHP. The version of this software hosted on the remote web server fails to sanitize input to the |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 16216 |
published | 2005-01-19 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/16216 |
title | Siteman < 1.1.11 Multiple Vulnerabilities |
code |
|