Secunia Advisory SA29722
Prozilla Reviews "DeleteUser.php" Security Bypass
|
|
|
Descriptiont0pP8uZz has reported a vulnerability in Prozilla Reviews, which can be exploited by malicious people to bypass certain security restrictions.
The vulnerability is caused due to insufficient access restrictions of the siteadmin/DeleteUser.php script. This can be exploited to delete arbitrary users by directly accessing the vulnerable script. Solution Restrict access to the affected script (e.g. with ".htaccess").
Provided and/or discovered by t0pP8uZz
Changelog
Further details available in Customer Area
Original Advisory http://milw0rm.com/exploits/5387
Deep Links
Links available in Customer Area
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new
versions, exploits, faulty patches, links, and other relevant data by
posting comments to this Advisory. You can also send this information to
vuln@secunia.com
No posts yet
|
|

You must be logged in to post a comment.
|
|
|