Tutorialcms CVE-2007-2822 Security Bypass Vulnerability

Tutorialcms is prone to a security bypass vulnerability. TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.


 

Privacy Statement
Copyright 2010, SecurityFocus