CVE-2005-1005 Information

Description

ProfitCode PayProCart 3.0 allows remote attackers to bypass authentication and gain administrative privileges to the admin control panel as demonstrated via a direct request to adminshop/index.php with hex-encoded .. sequences in the ftoedit parameter.

Reference

http://marc.info/?l=bugtraq&m=111264602406090&w=2 http://secunia.com/advisories/14832 http://securitytracker.com/id?1013640 https://exchange.xforce.ibmcloud.com/vulnerabilities/19956

Share on: