CVE Database
/

CVE-2005-4458

Back to search

CVE-2005-4458

Published: Dec 21, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Group.pm in Metadot Portal Server 6.4.4 and earlier does not properly reset the $IS_OWNER, $IS_ADMIN, and $IS_MANAGER global variables when performing checks for special privileges, which allows users to gain administrator privileges by adding themselves to the SITE_MGR group.

VendorProductVersions

n/a

n/a

affected
n/a

References

ADV-2005-3030
vdb-entry
x_refsource_VUPEN
287
third-party-advisory
x_refsource_SREASON
18137
third-party-advisory
x_refsource_SECUNIA
15975
vdb-entry
x_refsource_BID
22014
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now