ASPjar Guestbook 1.00 allows remote attackers to delete arbitrary messages accessing the delete.asp administrative script with certain cookie values set to "true".
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/9006 | vdb entry |
http://online.securityfocus.com/archive/82/270970 | mailing list |
http://www.securityfocus.com/bid/4671 | vdb entry |
http://www.ifrance.com/kitetoua/tuto/5holes4.txt | vendor advisory |