phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain access to the admin control panel via a direct request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Phpbazar | Smartisoft | * | 2.1.1 (including) |
Phpbazar | Smartisoft | 2.0.2 (including) | 2.0.2 (including) |
Phpbazar | Smartisoft | 2.1.0 (including) | 2.1.0 (including) |
Phpbazar | Smartisoft | 2.1.1fix (including) | 2.1.1fix (including) |