Security Advisory

CVE-2009-1771

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2009-05-22 18:00:00
Last updated 2024-08-07 05:27:54
Assigner mitre
State PUBLISHED

Description

index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters.