Description: Liz0ziM has reported a vulnerability in AdultScript, which can be exploited by malicious people to bypass certain security restrictions and to disclose sensitive information.
The admin/administrator.php script does not properly restrict access to logged-in users and can be exploited with an HTTP client that does not follow redirects. This can be exploited to e.g. disclose the administrator username and password.
The vulnerability is reported in version 1.6. Other versions may also be affected.
Solution: Restrict access to the "admin/" directory (e.g. with ".htaccess").
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.