Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PAFaq Database Unauthorized Access Vulnerability

paFaq is prone to an unauthorized access vulnerability regarding the database. This issue is a result of the application failing to perform access validation on the 'backup.php' script. A remote unauthenticated user can invoke the script and retrieve a complete backup of the application database.

A remote attacker could exploit this vulnerability to authenticate to the application using a retrieved administrator username and password hash.







 

Privacy Statement
Copyright 2009, SecurityFocus