vendor:
pL-PHP
by:
Omni
5.5
CVSS
MEDIUM
SQL Injection - Admin Access Bypass, Global Variable problem - Admin Access Bypass
89, 20
CWE
Product Name: pL-PHP
Affected Version From: beta 0.9
Affected Version To: Prior version may also be affected
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
pL-PHP beta 0.9 – MULTIPLE VULNERABILITIES
The pL-PHP beta 0.9 version is affected by multiple vulnerabilities. The first vulnerability is an SQL Injection that allows an attacker to bypass the admin access. The second vulnerability is a global variable problem that also allows an attacker to bypass the admin access.
Mitigation:
To mitigate the SQL Injection vulnerability, it is recommended to properly sanitize the variables $login and $pass before using them. To mitigate the global variable problem, it is recommended to fix the bug in the admin.php source code.