admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Orion-blog | Orion-blog | 2.0 (including) | 2.0 (including) |
References