Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

pPIM Multiple Remote Vulnerabilities

pPIM is prone to multiple vulnerabilities, including two security-bypass issues, a cross-site scripting issue, and a file-upload issue.

Attackers can exploit these issues to:

- execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site
- steal cookie-based authentication credentials
- delete local files within the context of the webserver process
- upload arbitrary PHP scripts and execute them in the context of the webserver
- change user passwords

These issues affect pPIM 1.0 and prior versions.







 

Privacy Statement
Copyright 2008, SecurityFocus