Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6414 (AdultScript)

BugsAlert Home > CVE-2007-6414 (AdultScript)
 
 

admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to bypass authentication and obtain administrative credentials via a direct request. NOTE: this can be leveraged for arbitrary code execution through a request to admin/videolinks_view.php.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6414

Learn more about CVE-2007-6414 (AdultScript)
 
Tags: cve-2007-6414 adultscript

Related Items

      TROJ_AGENT.AFPY

      Debian: New Linux 2.6.18 packages fix several vulnerabilities

      FrSIRT - Novell iManager Property Book Pages Deletion Weakness

      Lycos FileUploader Module File Upload Component ActiveX Control Buffer Overflow

      CVE-2008-0992 (Mac OS X, Mac OS X Server)

      Slackware update for libpng

      Gentoo update for vmware

 

Pixel