Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended restrictions and gain privileges via a direct request to admin.home.php after visiting admin.php.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://www.exploit-db.com/exploits/8605 | exploit |
http://osvdb.org/54204 | vdb entry |
http://www.securityfocus.com/bid/34809 | vdb entry |
http://secunia.com/advisories/34994 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50306 | vdb entry |