blog.ziaurrashid.com
https://blog.ziaurrashid.com/idor-on-proconf-peer-reviewand-conference-management-system CVE-2018-16606
MEDIUM
ProConf 6.0 - Insecure Direct Object Reference (IDOR)
Record summary
CVE-2018-16606 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.
Description
In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Organization, and Position) by changing the value of Paper ID (the pid parameter).
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBProConf 6.0 - Insecure Direct Object Reference (IDOR)ExploitDB exploitby ub3rsickNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-16606 packetstormsecurity.com
https://packetstormsecurity.com/files/149259/IDOR-On-ProConf-Peer-Review-And-Conference-Management-6.0-File-Disclosure.html