Allons_voter 1.0 allows remote attackers to bypass authentication and access certain administrative functionality via a direct request for (1) admin_ajouter.php or (2) admin_supprimer.php. NOTE: this could be leveraged to conduct cross-site scripting (XSS) attacks.
References
Configurations
History
No history.
Information
Published : 2007-02-12 19:28
Updated : 2018-10-16 16:34
NVD link : CVE-2007-0874
Mitre link : CVE-2007-0874
CVE.ORG link : CVE-2007-0874
JSON object : View
Products Affected
allons_voter
- allons_voter
CWE