The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/11301 | vdb entry |
http://securitytracker.com/id?1011484 | vdb entry |
http://echo.or.id/adv/adv07-y3dips-2004.txt | exploit vendor advisory |
http://marc.info/?l=bugtraq&m=109664986210763&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17571 | vdb entry |