Vulnerabilities > CVE-2007-1471 - Security Bypass vulnerability in Orion-Blog 2.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
orion-blog
exploit available

Summary

admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp.

Vulnerable Configurations

Part Description Count
Application
Orion-Blog
1

Exploit-Db

descriptionOrion-Blog 2.0 (AdminBlogNewsEdit.asp) Remote Auth Bypass Vuln. CVE-2007-1471. Webapps exploit for asp platform
idEDB-ID:3481
last seen2016-01-31
modified2007-03-15
published2007-03-15
reporterWiLdBoY
sourcehttps://www.exploit-db.com/download/3481/
titleOrion-Blog 2.0 AdminBlogNewsEdit.asp Remote Auth Bypass Vuln