Baal Smart Forms before 3.2 allows remote attackers to bypass authentication and obtain system access via a direct request to regadmin.php.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/17499 | vdb entry third party advisory |
http://secunia.com/advisories/12649/ | broken link third party advisory patch vendor advisory |
http://securitytracker.com/id?1011416 | patch exploit vdb entry third party advisory broken link |