|
Family: CGI abuses --> Category: infos
TrueGalerie admin access Vulnerability Scan
Vulnerability Scan Summary logs into the remote TrueGalerie installation
Detailed Explanation for this Vulnerability Test
The remote host is running TrueGalerie, an album management system
written in PHP.
There is a flaw in the version of TrueGalerie which may allow a possible hacker
to log in as the administrator without having to know the password, simply
by requesting the URL :
/admin.php?loggedin=1
A possible hacker may use this flaw to gain administrative rights on
this web server and modify its content.
Solution : Disable the option 'register_globals' in php.ini or replace
this set of CGI by something else
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.
|