CVE-2008-7172
08.09.2009, 10:30
Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administrator privileges via direct requests to admin.php with the (1) potd_delete, (2) potd, (3) vote_update, (4) vote, or (5) modifynews actions.Enginsight
Vendor | Product | Version |
---|---|---|
yanick_bourbeau | lightweight_news_portal | 1.0b:b |
𝑥
= Vulnerable software versions
Common Weakness Enumeration