generaloptions.php in Paul Tarjan Stanford Conference And Research Forum (SCARF) before 20070227 does not require the admin privilege, which allows remote attackers to reconfigure the application or its user accounts.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/30037 | vdb entry |
http://www.vupen.com/english/advisories/2007/0760 | vdb entry vendor advisory |
http://www.securityfocus.com/archive/1/460196/100/0/threaded | mailing list |
http://sourceforge.net/project/shownotes.php?group_id=177652&release_id=489633 | |
http://secunia.com/advisories/24311 | third party advisory vendor advisory |
http://www.securityfocus.com/archive/1/450679/100/0/threaded | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32700 | vdb entry |
http://www.securityfocus.com/bid/20934 | vdb entry |