CVE

Id
25360  
CVE No.
CVE-2007-2003  
Status
Candidate  
Description
InoutMailingListManager 3.1 and earlier sends a Location redirect header but does not exit after an authorization check fails, which allows remote attackers to access certain restricted functionality, and upload and execute arbitrary PHP code, by ignoring the redirect.  
Phase
Assigned (20070412)  
Votes
None (candidate not yet proposed)  
Comments