HIGH · 7.5

CVE-2006-1213

JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files director...

Vulnerability Description

JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directory, as demonstrated by using addadmin.asp to create a new administrator account.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
JiroBanner System1.0_experience

References

FAQ

What is CVE-2006-1213?

CVE-2006-1213 is a vulnerability with a CVSS score of 7.5 (HIGH). JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files director...

How severe is CVE-2006-1213?

CVE-2006-1213 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-1213?

Check the references section above for vendor advisories and patch information. Affected products include: Jiro Banner System.