Security Advisory
CVE-2004-2638
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The Admin Access With Levels plugin in osCommerce 1.5.1 allows remote attackers to access files in the "admin/" directory by modifying the in_login parameter to a non-zero value.