The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.php, which might allow remote attackers to gain access to the administration panel via a brute force attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ixprim_cms | Ixprim | 1.2 (including) | 1.2 (including) |