CVE-2005-4458
Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- metadot/metadot portal server
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/1012.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/18137
- http://securityreason.com/securityalert/287
- http://www.metadot.com/metadot/index.pl?iid=2632
- http://www.osvdb.org/22014
- http://www.securityfocus.com/archive/1/420002/100/0/threaded
- http://www.securityfocus.com/bid/15975Patch
- http://www.vupen.com/english/advisories/2005/3030
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23847
- http://archives.neohapsis.com/archives/fulldisclosure/2005-12/1012.htmlPatch, Vendor Advisory
- http://secunia.com/advisories/18137
- http://securityreason.com/securityalert/287
- http://www.metadot.com/metadot/index.pl?iid=2632
- http://www.osvdb.org/22014
- http://www.securityfocus.com/archive/1/420002/100/0/threaded
- http://www.securityfocus.com/bid/15975Patch
- http://www.vupen.com/english/advisories/2005/3030
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23847
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.