admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of the admin account by setting the zapis parameter to "ok" and providing modified admin_mail, login, and pass parameters.
Link | Tags |
---|---|
http://osvdb.org/34519 | vdb entry |
https://www.exploit-db.com/exploits/3506 | exploit |