|
phpWebSite contains a flaw that may allow a malicious user to force an administrator to execute malicious code. The issue is triggered when a malicious user sends specially crafted code to an administrator which forces commands to be executed via POST requests instead of GET requests, bypassing some authentication checks. It is possible that the flaw may allow a remote attacker to create an adminsitrative account and/or take over the system resulting in a loss of confidentiality and/or integrity.
|