MEDIUM · 5.5

CVE-2006-4586

The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user sett...

Vulnerability Description

The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php, and changing a password via /membres/change_mdp.php. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.

CVSS Score

5.5

MEDIUM

AV:N/AC:L/Au:S/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Tr ForumTr Forum2.0

References

FAQ

What is CVE-2006-4586?

CVE-2006-4586 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user sett...

How severe is CVE-2006-4586?

CVE-2006-4586 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-4586?

Check the references section above for vendor advisories and patch information. Affected products include: Tr Forum Tr Forum.