admin/index.php in AV Arcade 2.1b grants administrative privileges when the ava_userid cookie value is 1, which allows remote attackers to perform certain administrative actions.
References
Configurations
History
21 Nov 2024, 00:33
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/38952 - | |
References | () http://securityreason.com/securityalert/2871 - | |
References | () http://www.securityfocus.com/archive/1/472666/100/0/threaded - | |
References | () http://www.securityfocus.com/bid/24736/info - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/35234 - |
Information
Published : 2007-07-10 01:30
Updated : 2024-11-21 00:33
NVD link : CVE-2007-3643
Mitre link : CVE-2007-3643
CVE.ORG link : CVE-2007-3643
JSON object : View
Products Affected
av_scripts
- av_arcade
CWE