The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the in_login parameter to a non-zero value.
Link | Tags |
---|---|
http://secwatch.org/advisories/1007857 | patch vendor advisory |
http://secunia.com/advisories/11473 | third party advisory patch vendor advisory |
http://www.securityfocus.com/bid/10235 | vdb entry |
http://www.osvdb.org/5717 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16009 | vdb entry |