PHPGEDVIEW 2.61 allows remote attackers to reinstall the software and change the administrator password via a direct HTTP request to editconfig.php.
Link | Tags |
---|---|
http://secunia.com/advisories/10565 | third party advisory |
http://marc.info/?l=bugtraq&m=107340840209453&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/14161 | vdb entry |
http://www.osvdb.org/3403 | vdb entry |