1Two News 1.0 allows remote attackers to (1) delete images for new stories via a direct request to admin/delete.php or (2) upload arbitrary images via a direct request to admin/upload.php.
References
Link | Resource |
---|---|
http://securitytracker.com/id?1013960 | Exploit Patch Vendor Advisory |
Configurations
Information
Published : 2005-05-13 21:00
Updated : 2008-09-05 13:49
NVD link : CVE-2005-1583
Mitre link : CVE-2005-1583
JSON object : View
CWE
Products Affected
1two
- 1two_news