Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct request to admin.php with the Login parameter set to 1.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/21625 | vdb entry exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/30921 | vdb entry |
https://www.exploit-db.com/exploits/2938 | exploit |
http://www.securityfocus.com/data/vulnerabilities/exploits/21625.html | exploit |