delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Max.blog |
Mzbservices |
1.0.6 (including) |
1.0.6 (including) |
References