Security Advisory

CVE-2008-0391

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-01-23 01:00:00
Last updated 2024-08-07 07:46:53
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a modified lilil parameter, in conjunction with the ubild and pa parameters.