phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpprofiles | Phpprofiles | 2.1.0 (including) | 2.1.0 (including) |