20070215 [milw0rm] exploit 3305mailing list
http://attrition.org/pipermail/vim/2007-February/001341.html CVE-2007-0873
nabopoll 1.2 - Remote Unprotected Admin Section
Record summary
CVE-2007-0873 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) config_edit.php, (2) template_edit.php, or (3) survey_edit.php in admin/.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBnabopoll 1.2 - Remote Unprotected Admin SectionExploitDB exploitby sn0oPyNot analyzed1 file
References
9forums.avenir-geopolitique.net
http://forums.avenir-geopolitique.net/viewtopic.php?t=2643 33692vdb entry
http://osvdb.org/33692 2232Third-party advisory
http://securityreason.com/securityalert/2232 20070210 nabopoll 1.1.2 sensitive file (admin without password)mailing list
http://www.securityfocus.com/archive/1/459655/100/0/threaded 22509vdb entry
http://www.securityfocus.com/bid/22509 nabopoll-adminscripts-unauthorized-access(32472)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/32472 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2007-0873 3305exploit
https://www.exploit-db.com/exploits/3305