|
PHP Advanced Transfer Manager Remote Unauthorized Access Vulnerability
PHP Advanced Transfer Manager can allow remote attackers to gain unauthorized access. Access to sensitive files containing authentication credentials is not restricted, therefore an attacker can simply issue a GET request to obtain a user's password hash. This information can then allow them to successfully authenticate to the service using a cookie. PHP Advanced Transfer Manager 1.30 is reported to be vulnerable. Other versions may be affected as well. |
|
|
Privacy Statement |