Vulnerability Description
The WebAdmin interface in TeamSpeak Server 2.0.20.1 allows remote authenticated users with the ServerAdmin flag to assign Registered users certain privileges, resulting in a privilege set that extends beyond that ServerAdmin's own servers, as demonstrated by the (1) AdminAddServer, (2) AdminDeleteServer, (3) AdminStartServer, and (4) AdminStopServer privileges; and administration of arbitrary virtual servers via a request to a .tscmd URI with a modified serverid parameter, as demonstrated by (a) add_server.tscmd, (b) ask_delete_server.tscmd, (c) start_server.tscmd, and (d) stop_server.tscmd.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teamspeak | Web Server | 2.0.20.1 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2007-05/0165.html
- http://osvdb.org/36047
- http://secunia.com/advisories/25242
- http://securityvulns.com/Rdocument6.htmlExploit
- http://www.securityfocus.com/archive/1/477424/100/0/threaded
- http://www.securityfocus.com/bid/23935
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34254
- http://archives.neohapsis.com/archives/fulldisclosure/2007-05/0165.html
- http://osvdb.org/36047
- http://secunia.com/advisories/25242
- http://securityvulns.com/Rdocument6.htmlExploit
- http://www.securityfocus.com/archive/1/477424/100/0/threaded
- http://www.securityfocus.com/bid/23935
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34254
FAQ
What is CVE-2007-4529?
CVE-2007-4529 is a vulnerability with a CVSS score of 8.5 (HIGH). The WebAdmin interface in TeamSpeak Server 2.0.20.1 allows remote authenticated users with the ServerAdmin flag to assign Registered users certain privileges, resulting in a privilege set that extends...
How severe is CVE-2007-4529?
CVE-2007-4529 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4529?
Check the references section above for vendor advisories and patch information. Affected products include: Teamspeak Web Server.