PhotoDB 1.4 Administrator Access...

- AV AC AU C I A
发布: 2002-05-04
修订: 2025-04-13

PhotoDB 1.4 is a PHP based photo management and display system. It makes use of a simple authentication script that can easily be bypassed to gain administrator access. This is done by submitting a request with the following parameters to the administrator's page: /[THEADMINSPAGE]?PHPSESSID=abc123&Time=9999999999999&rmtusername=hop&rmtpassword=hop&accessevel=-5 The values for the parameters given above circumvent the simple checks the script employs, as described in the analysis by "frog frog".

0%
暂无可用Exp或PoC
当前有0条受影响产品信息