HIGH
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters
Published May 22, 2009
7.5
HIGHCVSS 2.0
EPSS 3.76%
Description
Affected products
Remediation
References (3)
Change history (0)
No recorded changes yet.