CVE

Id
6108  
CVE No.
CVE-2002-1726  
Status
Candidate  
Description
secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.  
Phase
Assigned (20050621)  
Votes
None (candidate not yet proposed)  
Comments