Vulnerabilities > CVE-2005-4458 - Privilege Escalation vulnerability in MetaDot Portal Server Site_Mgr Group
Attack vector
NETWORK Attack complexity
LOW Privileges required
SINGLE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.
Vulnerable Configurations
References
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/1012.html
- http://secunia.com/advisories/18137
- http://securityreason.com/securityalert/287
- http://www.metadot.com/metadot/index.pl?iid=2632
- http://www.osvdb.org/22014
- http://www.securityfocus.com/archive/1/420002/100/0/threaded
- http://www.securityfocus.com/bid/15975
- http://www.vupen.com/english/advisories/2005/3030
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23847