PHPoto Picture_view Script Unauthorized Access Vulnerability

PHPoto is prone to an unauthorized access vulnerability that can allow remote users to view any pictures hosted on a site, regardless of the user's privileges.

PHPoto versions PHPoto 0.4.0-pre-5 and prior are prone to this issue.


 

Privacy Statement
Copyright 2010, SecurityFocus