CVE-2009-2125

delete_bug.php in Elvin before 1.2.1 does not require administrative privileges, which allows remote authenticated users to bypass intended access restrictions and delete arbitrary bugs.
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:elvinbts:elvinbts:*:*:*:*:*:*:*:*
cpe:2.3:a:elvinbts:elvinbts:1.1.0:*:*:*:*:*:*:*

Information

Published : 2009-06-19 11:00

Updated : 2009-06-22 21:00


NVD link : CVE-2009-2125

Mitre link : CVE-2009-2125


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

elvinbts

  • elvinbts