login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpwishlist | Phpwishlist | 0.1.9 (including) | 0.1.9 (including) |
Phpwishlist | Phpwishlist | 0.1.10 (including) | 0.1.10 (including) |
Phpwishlist | Phpwishlist | 0.1.11 (including) | 0.1.11 (including) |
Phpwishlist | Phpwishlist | 0.1.12 (including) | 0.1.12 (including) |
Phpwishlist | Phpwishlist | 0.1.13 (including) | 0.1.13 (including) |
Phpwishlist | Phpwishlist | 0.1.14 (including) | 0.1.14 (including) |