CVE-2005-4174 Information

Description

eFiction 1.0 1.1 and 2.0 in unspecified environments might allow remote attackers to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear whether this is a vulnerability in eFiction itself or the result of incorrect system administration practices e.g. by not removing utility scripts once they have been used.

Reference

http://archives.neohapsis.com/archives/bugtraq/2005-11/0301.html http://rgod.altervista.org/efiction2_xpl.html http://secunia.com/advisories/17777 http://securityreason.com/securityalert/206 http://securitytracker.com/id?1015273 http://www.efiction.wallflowergirl.com/forums/viewtopic.php?t=1555 http://www.securityfocus.com/bid/15568

Share on: