A File Deletion vulnerability exists in TinyShop 3.1.1 in the back_list parameter in controllers\admin.php, which could let a malicious user delete any file such as install.lock to reinstall cms.
Link | Tags |
---|---|
http://tinyrise.com/ | broken link |
http://tinyrise.com/down.html | broken link |
https://imgur.com/dg1DM5T | third party advisory exploit |
https://imgur.com/pA8OWxa | third party advisory exploit |