5.5
CVSSv2

CVE-2006-4586

Published: 06/09/2006 Updated: 17/10/2018
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 555
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php, and changing a password via /membres/change_mdp.php. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated malicious users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

tr forum tr forum 2.0

Exploits

#!/usr/bin/perl # # Affectedscr: Tr Forum V20 # PocID: 10060903 # Type: SQL Injection, Bypass Security Restriction # Risklevel: Medium # VendorStatus: Unpatched # Srcdownload: comscriptscom/scripts/phptr-forum1579html # Poclink: acid-rootnewfr/poc/10060903txt # Credits: DarkFig # # /membres/modi ...