7.5
CVSSv2

CVE-2006-4584

Published: 06/09/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Tr Forum 2.0 allows remote malicious users to bypass authentication and add an administrative account via the login and password parameters to admin/insert_admin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

tr forum tr forum 2.0

Exploits

#!/usr/bin/perl # # Affectedscr: Tr Forum V20 # PocID: 10060903 # Type: SQL Injection, Bypass Security Restriction # Risklevel: Medium # VendorStatus: Unpatched # Srcdownload: comscriptscom/scripts/phptr-forum1579html # Poclink: acid-rootnewfr/poc/10060903txt # Credits: DarkFig # # /membres/modi ...
======================================================================================== | # Title : TR Forum 15 insert admin CSRF Vulnerability | # Author : EL-KAHINA | # email : No-Mail | # Home ...