CVE-2007-2713

ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request for the admin/ URI.
Configurations

Configuration 1

cpe:2.3:a:ifusionservices:ifdate:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ifusionservices:ifdate:2.0:*:*:*:*:*:*:*

Information

Published : 2007-05-16 10:19

Updated : 2018-10-16 04:45


NVD link : CVE-2007-2713

Mitre link : CVE-2007-2713

Products Affected
No products.
CWE
CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')