Vulnerabilities > CVE-2007-2822 - Security Bypass vulnerability in Tutorialcms

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
wavelink-media
critical
exploit available

Summary

TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.

Vulnerable Configurations

Part Description Count
Application
Wavelink_Media
1

Exploit-Db

descriptionTutorialCMS <= 1.01 Authentication Bypass Vulnerability. CVE-2007-2822. Webapps exploit for php platform
fileexploits/php/webapps/3963.txt
idEDB-ID:3963
last seen2016-01-31
modified2007-05-21
platformphp
port
published2007-05-21
reporterSilentz
sourcehttps://www.exploit-db.com/download/3963/
titleTutorialCMS <= 1.01 - Authentication Bypass Vulnerability
typewebapps