CVE Vulnerabilities

CVE-2005-4458

Published: Dec 21, 2005 | Modified: Oct 19, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9 HIGH
AV:N/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.

Affected Software

Name Vendor Start Version End Version
Metadot_portal_server Metadot 5.5.2.1 (including) 5.5.2.1 (including)
Metadot_portal_server Metadot 5.6.4 (including) 5.6.4 (including)
Metadot_portal_server Metadot 5.6.4.1 (including) 5.6.4.1 (including)
Metadot_portal_server Metadot 5.6.4.2 (including) 5.6.4.2 (including)
Metadot_portal_server Metadot 5.6.4.3 (including) 5.6.4.3 (including)
Metadot_portal_server Metadot 5.6.5 (including) 5.6.5 (including)
Metadot_portal_server Metadot 5.6.5.1 (including) 5.6.5.1 (including)
Metadot_portal_server Metadot 5.6.5.2 (including) 5.6.5.2 (including)
Metadot_portal_server Metadot 5.6.5.3 (including) 5.6.5.3 (including)
Metadot_portal_server Metadot 5.6.5.3.1 (including) 5.6.5.3.1 (including)
Metadot_portal_server Metadot 5.6.5.4b5 (including) 5.6.5.4b5 (including)
Metadot_portal_server Metadot 5.6.6 (including) 5.6.6 (including)
Metadot_portal_server Metadot 6.4 (including) 6.4 (including)
Metadot_portal_server Metadot 6.4.1 (including) 6.4.1 (including)
Metadot_portal_server Metadot 6.4.2 (including) 6.4.2 (including)
Metadot_portal_server Metadot 6.4.3 (including) 6.4.3 (including)
Metadot_portal_server Metadot 6.4.4 (including) 6.4.4 (including)

References