The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.
References
Configurations
History
No history.
Information
Published : 2003-12-31 05:00
Updated : 2017-07-29 01:29
NVD link : CVE-2003-1488
Mitre link : CVE-2003-1488
CVE.ORG link : CVE-2003-1488
JSON object : View
Products Affected
truelogik
- truegalerie
CWE
CWE-20
Improper Input Validation