ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request for the admin/ URI.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2007-05-16 03:19
Updated : 2018-10-16 09:45
NVD link : CVE-2007-2713
Mitre link : CVE-2007-2713
JSON object : View
CWE
Products Affected
ifusionservices
- ifdate