Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user.
Link | Tags |
---|---|
http://securitytracker.com/id?1015307 | exploit vdb entry vendor advisory |