secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.
References
Configurations
History
20 Nov 2024, 23:41
Type | Values Removed | Values Added |
---|---|---|
References | () http://online.securityfocus.com/archive/82/270970 - | |
References | () http://www.ifrance.com/kitetoua/tuto/5holes4.txt - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/4669 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/9002 - |
Information
Published : 2002-12-31 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2002-1726
Mitre link : CVE-2002-1726
CVE.ORG link : CVE-2002-1726
JSON object : View
Products Affected
brokenbytes
- photodb
CWE