7.5
CVSSv2

CVE-2006-2737

Published: 01/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

utilities/register.asp in Nukedit 4.9.6 and previous versions allows remote malicious users to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action.

Vulnerable Product Search on Vulmon Subscribe to Product

nukedit nukedit

nukedit nukedit 4.9.2

nukedit nukedit 4.9.3

nukedit nukedit 4.9.0

nukedit nukedit 4.9.1

Exploits

################ KAPDA - Security Science Researchers Institute ################# #Advisory : wwwkapdair/advisory-337html #Vendor : wwwnukeditcom/ #What is : Nukedit is a Free Content Management #Vulnerability : Unauthorized Admin Add Exploit if "registerasp" be enable! #Discovered : 3nitro - farhadkey {AT} kapda [d0t] ir #Vulne ...