admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] parameter to 1 during a login action.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Php-update |
Php-update |
* |
2.7 (including) |
References