CVE-2007-4932 Information

Description

admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing which allows remote attackers to access the admin panel.

Reference

http://osvdb.org/40149 http://secunia.com/advisories/26840 http://www.securityfocus.com/bid/25695 https://exchange.xforce.ibmcloud.com/vulnerabilities/36646 https://www.exploit-db.com/exploits/4419

Share on: