CVE Vulnerabilities

CVE-2006-4782

Published: Sep 14, 2006 | Modified: Oct 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.4 MEDIUM
AV:N/AC:H/Au:N/C:C/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain sensitive information stored in the database via a modified userID parameter in a write action to admin/database.php.

Affected Software

Name Vendor Start Version End Version
Webspell Webspell * 4.01.01 (including)
Webspell Webspell 4.0 (including) 4.0 (including)
Webspell Webspell 4.1 (including) 4.1 (including)
Webspell Webspell 4.1.1 (including) 4.1.1 (including)

References