secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.
Link | Tags |
---|---|
http://online.securityfocus.com/archive/82/270970 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/9002 | vdb entry |
http://www.securityfocus.com/bid/4669 | vdb entry |
http://www.ifrance.com/kitetoua/tuto/5holes4.txt | vendor advisory |