Sign in
CVE-2003-1488
CVE-2003-1488
Description
The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.
Impact
CVSS v2 : 6.4 MEDIUM
Type
CWE-20
Attack Vector
CVSSv2 Vector : AV:N/AC:L/Au:N/C:P/I:P/A:N
Quick links
CVE
,
NVD
,
CERT
,
Metasploit
,
Exploit-db
,
Fulldisc
,
Bugtraq
,
Microsoft
,
Red Hat
,
Debian
, GitHub
code
/
issues
,
Google
References
http://marc.info/?l=vulnwatch&m=105128431109082&w=2
http://secunia.com/advisories/8683
http://www.securityfocus.com/bid/7427
https://exchange.xforce.ibmcloud.com/vulnerabilities/11886
FAQ
Terms of service
Privacy policy