admin.php in dB Masters Multimedia Links Directory 3.1.3 allows remote attackers to bypass authentication and gain administrative access via a certain value of the admin_log cookie.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://packetstormsecurity.org/0912-exploits/dbmastersmm-insecure.txt | exploit |
http://www.securityfocus.com/bid/37517 | vdb entry exploit |
http://secunia.com/advisories/37985 | third party advisory vendor advisory |
http://www.osvdb.org/61393 | vdb entry |