admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of the admin account by setting the zapis parameter to ok and providing modified admin_mail, login, and pass parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Guestbara | Guestbara | * | 1.2 (including) |