Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wd_guestbook | Webmasters-debutants | 2.8 (including) | 2.8 (including) |