cve/2007/CVE-2007-2822.md
2024-05-26 14:27:05 +02:00

714 B

CVE-2007-2822

Description

TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.

POC

Reference

Github

No PoCs found on GitHub currently.