preferences.php in Simple Internet Publishing System (SIPS) before 0.3.1 allows remote attackers to gain administrative privileges via a linebreak in the theme field followed by the Status::admin command, which causes the Status line to be entered into the password file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sips | Sips | 0.2.4 (including) | 0.2.4 (including) |
Sips | Sips | 0.3.0 (including) | 0.3.0 (including) |
Sips | Sips | 0.3.0pl1 (including) | 0.3.0pl1 (including) |
Sips | Sips | 0.3.0pl2 (including) | 0.3.0pl2 (including) |