CVE-2009-1780
22.05.2009, 20:30
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.Enginsight
Vendor | Product | Version |
---|---|---|
frax | php_recommend | 𝑥 ≤ 1.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration