HIGH
AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to inject a credential variable setting and obtain administrative access via a direct request to admin/changeinfo.php
Published May 21, 2007
10.0
HIGHCVSS 2.0
EPSS 8.62%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.