CVE-2008-7172 Information
Feb 14, 2021
cve
Description
Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality which allows remote attackers to gain administrator privileges via direct requests to admin.php with the (1) potd_delete (2) potd (3) vote_update (4) vote or (5) modifynews actions.
Reference
http://www.securityfocus.com/bid/29848 https://exchange.xforce.ibmcloud.com/vulnerabilities/43225 https://www.exploit-db.com/exploits/5873
Share on: