CVE-2009-3168
11.09.2009, 20:30
Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request.Enginsight
Vendor | Product | Version |
---|---|---|
mevin | basic_php_events_lister | 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References