[] NeoSense

UtilMind Solutions Site News 1.1 - Authentication Bypass

Author: anonymous
type: webapps
platform: cgi
port: 
date_added: 2004-09-07 
date_updated: 2013-03-04 
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/11126/info

Reportedly UtilMind Solutions Site News is affected by an authentication bypass vulnerability. This issue is due to an access validation error.

An unauthenticated attacker can leverage this issue to display and manipulate arbitrary news items.

http://www.example.com/ sitenews.cgi?update\?oldsubject=OLD_SUBJ&subject=NEW_SUBJ&name=ANY_NAME&issue=ISSUE&message=MESSAGE