MyCO Guestbook 1.0 stores the admin directory under the web document root with insufficient access control, which allows remote attackers to perform unspecified privileged actions by directly accessing files via a URL.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/423565/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/24438 | vdb entry |