Vulnerabilities > CVE-2006-4427 - Unspecified vulnerability in Efiction
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN efiction
exploit available
Summary
index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (1) adminloggedin, (2) loggedin, and (3) level parameters to "1".
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |
Exploit-Db
description | eFiction < 2.0.7 Remote Admin Authentication Bypass Vulnerability. CVE-2006-4427. Webapps exploit for php platform |
file | exploits/php/webapps/2255.txt |
id | EDB-ID:2255 |
last seen | 2016-01-31 |
modified | 2006-08-25 |
platform | php |
port | |
published | 2006-08-25 |
reporter | Vipsta |
source | https://www.exploit-db.com/download/2255/ |
title | eFiction < 2.0.7 - Remote Admin Authentication Bypass Vulnerability |
type | webapps |
References
- http://efiction.org/forums/index.php?topic=3698
- http://efiction.org/forums/index.php?topic=3698
- http://secunia.com/advisories/21625
- http://secunia.com/advisories/21625
- http://www.osvdb.org/28237
- http://www.osvdb.org/28237
- http://www.securityfocus.com/bid/19717
- http://www.securityfocus.com/bid/19717
- http://www.vupen.com/english/advisories/2006/3392
- http://www.vupen.com/english/advisories/2006/3392
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28595
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28595
- https://www.exploit-db.com/exploits/2255
- https://www.exploit-db.com/exploits/2255