LinksCaffe 2.0/3.0 - Authentication Bypass

EDB-ID:

28442

CVE:

N/A




Platform:

PHP

Date:

2006-07-25


source: https://www.securityfocus.com/bid/19763/info

LinksCaffe is prone to an authentication-bypass vulnerability because of a lack of required authentication on the application's administrative script. An attacker can use administrative functions simply by knowing the script's name and location.

A successful exploit of this issue could allow an attacker to compromise the application, access or modify data, delete site content, or exploit vulnerabilities in the system or underlying database implementation. Other attacks are also possible.

Versions 2.0 and 3.0 are reported vulnerable; other versions may also be affected.

http://www.example.com/[path_to_linksCaffe]/Admin/admin1953.php