vendor:
Grayscale Blog
by:
omnipresent
7.5
CVSS
HIGH
Security Query Bypass
CWE
Product Name: Grayscale Blog
Affected Version From: 0.8.0
Affected Version To: 0.8.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Multiple Vulnerabilities in Grayscale Blog 0.8.0
A user can bypass security restrictions and add a user with Administrator Privilege in Grayscale Blog 0.8.0. Other files like addblog.php, editblog.php, editlinks.php, edit_users.php, and add_links.php are also affected by similar security issues.