upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file or have unspecified other impact via a direct request.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Shibby_shop |
Aspindir |
* |
2.2 (including) |
References