Papoo CMS 3.6, and possibly earlier, does not verify user...
Vulnerability Description
Papoo CMS 3.6, and possibly earlier, does not verify user privileges when accessing the backend administration plugins, which allows remote authenticated users to (1) read the entire database by accessing the database backup plugin via a devtools/templates/newdump_backend.html argument in the template parameter to interna/plugin.php, (2) create plugins, (3) remove plugins, (4) enable debug mode, and have other unspecified impact.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-3494
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.papoo.de/index/menuid/204/reporeid/215
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-June/064171.html
- http://www.securityfocus.com/bid/24634
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35032
- http://www.securityfocus.com/archive/1/472213/100/0/threaded
- http://osvdb.org/37542
- http://securityreason.com/securityalert/2853
More from papoo
View All →Affected Vendor
papoo
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.