JiRos Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directory, as demonstrated by using addadmin.asp to create a new administrator account.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Banner_system | Jiro | 1.0_experience (including) | 1.0_experience (including) |
Banner_system | Jiro | 1.0_professional (including) | 1.0_professional (including) |