|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
DUbanner contains a flaw that allows a remote attacker to gain administrative privileges. The issue is due to improper authentication verification when accessing different include files. While the program will require authentication for inc_edit.asp include file, it fails to authenticate on requests to the inc_menu.asp include file. This allows an attacker to directly request the file with administrative priveleges.
|
|
Classification |
Unknown or Incomplete
|
|
Solution |
Upgrade to version 3.1 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
DUbanner
 |
3.0 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|