admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication and obtain administrative credentials via a direct request. NOTE: this can be leveraged for arbitrary code execution through a request to admin/videolinks_view.php.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/39034 | vdb entry |
https://www.exploit-db.com/exploits/4731 | exploit |
http://secunia.com/advisories/28064 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/26870 | vdb entry exploit |