admin/index.php in AV Arcade 2.1b grants administrative privileges when the ava_userid cookie value is 1, which allows remote attackers to perform certain administrative actions.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/472666/100/0/threaded | mailing list |
http://securityreason.com/securityalert/2871 | third party advisory |
http://osvdb.org/38952 | vdb entry |
http://www.securityfocus.com/bid/24736/info | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35234 | vdb entry |