Authentication Bypass Vulnerability in PhotoDB 1.4

Authentication Bypass Vulnerability in PhotoDB 1.4

CVE-2002-1726 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

secure_inc.php in PhotoDB 1.4 allows remote attackers to bypass authentication via a URL with a large Time parameter, non-empty rmtusername and rmtpassword parameter, and an accesslevel parameter that is lower than the access level of the requested page.

Learn more about our User Device Pen Test.