The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter.
Link | Tags |
---|---|
http://securitytracker.com/id?1014415 | vdb entry exploit |
http://marc.info/?l=bugtraq&m=112076117708139&w=2 | mailing list |
http://secunia.com/advisories/15936 | patch vendor advisory third party advisory |