Vulnerabilities > CVE-2006-4586 - SQL Injection And Authentication Bypass vulnerability in TR Forum TR Forum 2.0

047910
CVSS 5.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
tr-forum
exploit available

Summary

The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php, and changing a password via /membres/change_mdp.php. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.

Vulnerable Configurations

Part Description Count
Application
Tr_Forum
1

Exploit-Db

descriptionTr Forum 2.0 SQL Injection / Bypass Security Restriction Exploit. CVE-2006-4584,CVE-2006-4586. Webapps exploit for php platform
fileexploits/php/webapps/2297.pl
idEDB-ID:2297
last seen2016-01-31
modified2006-09-04
platformphp
port
published2006-09-04
reporterDarkFig
sourcehttps://www.exploit-db.com/download/2297/
titleTr Forum 2.0 - SQL Injection / Bypass Security Restriction Exploit
typewebapps