ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request for the admin/ URI.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2007-05-16 10:19
Updated : 2025-04-09 00:30
NVD link : CVE-2007-2713
Mitre link : CVE-2007-2713
CVE.ORG link : CVE-2007-2713
JSON object : View
Products Affected
ifusionservices
- ifdate
CWE