Heap
23-09-08, 02:47
useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account.
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4167)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-4167)