vendor:
phpBazar
by:
Net_Spy
8,8
CVSS
HIGH
phpBazar admin information discloser
N/A
CWE
Product Name: phpBazar
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
phpBazar admin information discloser Vulnerability
phpBazar is vulnerable to an information discloser vulnerability. This vulnerability allows an attacker to view the admin panel of the website without authentication. This vulnerability is caused due to the improper validation of the ‘action’ parameter in the ‘admin.php’ script. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable script.
Mitigation:
Upgrade to the latest version of phpBazar.