The dologin function in guestbook.php in KvGuestbook 1.0 Beta allows remote attackers to gain administrative privileges, probably via modified $mysql['pass'] and $gbpass variables.
Link | Tags |
---|---|
http://osvdb.org/33710 | vdb entry |
http://securityreason.com/securityalert/2246 | third party advisory |
http://www.securityfocus.com/archive/1/459799/100/0/threaded | mailing list |