CVE Vulnerabilities

CVE-2004-2257

Direct Request ('Forced Browsing')

Published: Dec 31, 2004 | Modified: Jan 25, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

phpMyFAQ 1.4.0 allows remote attackers to access the Image Manager to upload or delete images without authorization via a direct request.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

Name Vendor Start Version End Version
Phpmyfaq Phpmyfaq 1.4.0 (including) 1.4.0 (including)

Potential Mitigations

References