The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininfo cookie to "<?php" or "?>", which is present in the password file and probably passes an insufficient comparison.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/42464 | vdb entry |
http://www.securityfocus.com/bid/29243 | vdb entry exploit |
http://secunia.com/advisories/30279 | third party advisory vendor advisory |
https://www.exploit-db.com/exploits/5628 | exploit |