CVE-2007-5817 Information

Description

dialog.php in CONTENTCustomizer 3.1mp and earlier allows remote attackers to perform certain privileged actions via a (1) del (2) delbackup (3) res or (4) ren action. NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) and possibly other attacks.

Reference

http://packetstorm.linuxsecurity.com/0710-exploits/contentcustom-disclose.txt http://www.securityfocus.com/bid/26437

Share on: