Heap
06-12-07, 17:36
index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value of true, as demonstrated by adding a user account.
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6234)
More... (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6234)