CVE-2008-6747 Information

Description

dotProject before 2.1.2 does not properly restrict access to administrative pages which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party information.

Reference

http://osvdb.org/46143 http://secunia.com/advisories/30470 http://sourceforge.net/project/shownotes.php?group_id=21656&release_id=616346 http://www.securityfocus.com/bid/29679 https://exchange.xforce.ibmcloud.com/vulnerabilities/43019

Share on: