Menu

#2 Privilege escalation

v1.0_(example)
open
nobody
5
2012-12-28
2007-01-18
Anonymous
No

If someone has a nonadmin acount for the webfilemanager to view uplaoded documents one can create a new admin user by calling the create function of the user administration e.g. http://hostip/?&to=admin&action=create&username=NewAdminUser&password=NewPassword&admin=on

After that the attacker can log in with the created user NewAdminUser and the password NewPassword and has admin privileges.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB