include.php in Shoutpro 1.0 might allow remote attackers to bypass IP ban restrictions via a URL in the path parameter that points to an alternate bannedips.php file. NOTE: this issue was originally reported as remote file inclusion, but CVE analysis suggests that this cannot be used for code execution.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/27111 | vdb entry |
http://www.securityfocus.com/archive/1/436997/30/4410/threaded | mailing list |
http://securityreason.com/securityalert/2303 | third party advisory |
http://www.securityfocus.com/archive/1/436975/30/4440/threaded | mailing list |