CVE Vulnerabilities

CVE-2005-4458

Published: Dec 21, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.

Affected Software

NameVendorStart VersionEnd Version
Metadot_portal_serverMetadot5.5.2.1 (including)5.5.2.1 (including)
Metadot_portal_serverMetadot5.6.4 (including)5.6.4 (including)
Metadot_portal_serverMetadot5.6.4.1 (including)5.6.4.1 (including)
Metadot_portal_serverMetadot5.6.4.2 (including)5.6.4.2 (including)
Metadot_portal_serverMetadot5.6.4.3 (including)5.6.4.3 (including)
Metadot_portal_serverMetadot5.6.5 (including)5.6.5 (including)
Metadot_portal_serverMetadot5.6.5.1 (including)5.6.5.1 (including)
Metadot_portal_serverMetadot5.6.5.2 (including)5.6.5.2 (including)
Metadot_portal_serverMetadot5.6.5.3 (including)5.6.5.3 (including)
Metadot_portal_serverMetadot5.6.5.3.1 (including)5.6.5.3.1 (including)
Metadot_portal_serverMetadot5.6.5.4b5 (including)5.6.5.4b5 (including)
Metadot_portal_serverMetadot5.6.6 (including)5.6.6 (including)
Metadot_portal_serverMetadot6.4 (including)6.4 (including)
Metadot_portal_serverMetadot6.4.1 (including)6.4.1 (including)
Metadot_portal_serverMetadot6.4.2 (including)6.4.2 (including)
Metadot_portal_serverMetadot6.4.3 (including)6.4.3 (including)
Metadot_portal_serverMetadot6.4.4 (including)6.4.4 (including)

References