Gonafish.com LinksCaffe 2.0 and 3.0 do not properly restrict access to administrator functions, which allows remote attackers to gain full administration rights via a direct request to Admin/admin1953.php.
Link | Tags |
---|---|
http://securitytracker.com/id?1016767 | vdb entry exploit |
http://www.securityfocus.com/archive/1/444636/100/0/threaded | mailing list |
http://securityreason.com/securityalert/1484 | third party advisory |