"value":"Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administrative activities, which allows remote attackers to (1) reinstall the application via a direct request for install/index.php; (2) delete the database via a do=delete_database QUERY_STRING to a renamed copy of install/index.php; or access the administration system, after guessing a filename, via a direct request for a file in (3) admin/ or (4) tech/."
},
{
"lang":"es",
"value":"Headstart Solutions DeskPRO no requiere autenticaci\u00f3n en ciertos ficheros y directorios asociados con actividades administrativas, lo que permite a atacantes remotos (1) reinstalar la aplicaci\u00f3n mediante una petici\u00f3n directa al install/index.php; (2) borrar la Base de Datos mediante do=delete_database QUERY_STRING en una copia renombrada del install/index.php; o acceder al sistema de administraci\u00f3n, despu\u00e9s de adivinar un nombre de fichero mediante una petici\u00f3n directa de un fichero en (3) admin/ o (4) tech/."