admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/4884 | exploit |
http://evilsentinel.altervista.org/forum/index.php?topic=49.0 | |
http://secunia.com/advisories/28427 | third party advisory patch |
http://www.securityfocus.com/bid/27227 | vdb entry |