CVE-2002-1726 Information

Description

secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter non-empty rmtusername and rmtpassword parameter and an accesslevel parameter that is lower than the access level of the requested page.

Reference

http://online.securityfocus.com/archive/82/270970 http://www.ifrance.com/kitetoua/tuto/5holes4.txt http://www.securityfocus.com/bid/4669 https://exchange.xforce.ibmcloud.com/vulnerabilities/9002

Share on: