CVE-2007-5835 Information

Description

Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account which allows remote attackers to cause a denial of service (overwritten files) and possibly obtain administrative access.

Reference

http://securityreason.com/securityalert/3343 http://www.securityfocus.com/archive/1/482732/100/0/threaded

Share on: