ifdate 2.x sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to obtain administrative access via a direct request for the admin/ URI.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ifdate | Ifusionservices | 2.0 (including) | 2.0 (including) |
Ifdate | Ifusionservices | 2.0.3 (including) | 2.0.3 (including) |