Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/36198 | exploit vdb entry third party advisory broken link |
http://www.osvdb.org/57595 | vdb entry broken link |
http://secunia.com/advisories/36525 | broken link third party advisory vendor advisory |
http://www.exploit-db.com/exploits/9558 | exploit vdb entry third party advisory broken link |
http://www.vupen.com/english/advisories/2009/2497 | vdb entry broken link vendor advisory |