Описание
Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion.
Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-8292
- https://www.abcprintf.com/view_download.php?id=17
- http://www.openwall.com/lists/oss-security/2019/10/02/1
- http://www.openwall.com/lists/oss-security/2019/12/23/1
- http://www.openwall.com/lists/oss-security/2019/12/23/2
- http://www.vapidlabs.com/advisory.php?v=210
Связанные уязвимости
CVSS3: 5.3
nvd
больше 6 лет назад
Online Store System v1.0 delete_product.php doesn't check to see if a user authtenticated or has administrative rights allowing arbitrary product deletion.