PHParanoid before 0.4 does not properly restrict access to the members area by unauthenticated users, which has unknown impact and remote attack vectors.
References
Link | Resource |
---|---|
http://sourceforge.net/project/shownotes.php?release_id=575358 | Patch Vendor Advisory |
http://secunia.com/advisories/28847 | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/40516 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-12-18 17:52
Updated : 2017-08-07 18:33
NVD link : CVE-2008-5673
Mitre link : CVE-2008-5673
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
phparanoid
- phparanoid