Vulnerabilities > CVE-2006-2737 - Unspecified vulnerability in Nukedit

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
nukedit
exploit available

Summary

utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action.

Vulnerable Configurations

Part Description Count
Application
Nukedit
5

Exploit-Db

descriptionNukedit CMS <= 4.9.6 Unauthorized Admin Add Exploit. CVE-2006-2737. Webapps exploit for asp platform
idEDB-ID:1850
last seen2016-01-31
modified2006-05-29
published2006-05-29
reporterFarhadKey
sourcehttps://www.exploit-db.com/download/1850/
titleNukedit CMS <= 4.9.6 Unauthorized Admin Add Exploit