SaveWebPortal Unauthorized Access Vulnerability

No exploit is required.

The following explanation and proof of concept URI is available:

a user can bypass admin check, calling this url:

http://www.example.com/saveweb/admin/PhpMyExplorer/editerfichier.php?chemin=.&fichier=header.php&type=Source


 

Privacy Statement
Copyright 2010, SecurityFocus