Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Geoblog v1 administrator bypass Jul 19 2007 08:14AM
joseph giron13 gmail com
Geoblog v1.

A vulnerability exists in geoblog version 1 (latest) that allows users to delete other peoples comments without administration credentials. It works on blogs too. Users can delete blogs without user credentials.

The reason why is because the listcomments.php and deletecomments.php ...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus