Vulnerabilities > CVE-2006-5777 - Security Bypass vulnerability in Creasito E-Commerce Content Manager

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
creasito
exploit available

Summary

Creasito E-Commerce Content Manager 1.3.08 allows remote attackers to bypass authentication and perform privileged functions via a non-empty finame parameter to (1) addnewcont.php, (2) adminpassw.php, (3) amministrazione.php, (4) artins.php, (5) bgcolor.php, (6) cancartcat.php, (7) canccat.php, (8) cancelart.php, (9) cancontsit.php, (10) chanpassamm.php, (11) dele.php, (12) delecat.php, (13) delecont.php, (14) emailall.php, (15) gestflashtempl.php, (16) gestmagart.php, (17) gestmagaz.php, (18) gestpre.php, (19) input.php, (20) input3.php, (21) insnucat.php, (22) instempflash.php, (23) mailfc.php, (24) modfdati.php, (25) rescont4.php, (26) ricordo1.php, (27) ricordo4.php, (28) tabcatalg.php, (29) tabcont.php, (30) tabcont3.php, (31) tabstile.php, (32) tabstile3.php, (33) testimmg.php, and (34) update.php in admin/. NOTE: some of these details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Creasito
1

Exploit-Db

descriptionCreasito E-Commerce Content Manager (admin) Authentication Bypass. CVE-2006-5777. Webapps exploit for php platform
fileexploits/php/webapps/2709.txt
idEDB-ID:2709
last seen2016-01-31
modified2006-11-03
platformphp
port
published2006-11-03
reporterSlimTim10
sourcehttps://www.exploit-db.com/download/2709/
titleCreasito E-Commerce Content Manager admin Authentication Bypass
typewebapps