change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter, possibly related to code injection.
References
Configurations
History
No history.
Information
Published : 2009-04-08 10:30
Updated : 2024-02-04 17:33
NVD link : CVE-2008-6665
Mitre link : CVE-2008-6665
CVE.ORG link : CVE-2008-6665
JSON object : View
Products Affected
anantasoft
- ananta_cms
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')