漏洞信息详情
Admin Access With Levels Plug-in For osCommerce访问控制绕过漏洞
漏洞简介
osCommerce 1.5.1版本中的Admin Access With Levels插件存在漏洞。远程攻击者可以通过修改非零值的in_login参数访问\"admin/\"目录中的文件。
漏洞公告
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] .
参考网址
来源: OSVDB 名称: 5717 链接:http://www.osvdb.org/5717 来源: secwatch.org 链接:http://secwatch.org/advisories/1007857 来源: SECUNIA 名称: 11473 链接:http://secunia.com/advisories/11473 来源: XF 名称: oscommerce-plugin-bypass-security(16009) 链接:http://xforce.iss.net/xforce/xfdb/16009 来源: BID 名称: 10235 链接:http://www.securityfocus.com/bid/10235
受影响实体
- Oscommerce Oscommerce:1.5.1<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...