Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

OrganicPHP PHP-Affiliate Details.PHP Hidden Field Authentication Bypassing Vulnerability

PHP-Affiliate is a freely available, open source web site affiliate software package. It is written in PHP, and designed for use on Unix, Linux, and Microsoft Windows operating systems.

PHP-Affiliate uses a hidden field when the details.php page is used to edit referral information. An attacker could exploit this to gain arbitrary access to the details of other users.







 

Privacy Statement
Copyright 2008, SecurityFocus