Required CVE Record Information
Description
settings.php in Reamday Enterprises Magic Downloads 1.1.3, when register_globals is enabled, allows remote attackers to modify program behavior, potentially bypassing authentication controls, via modified (1) action, (2) passwd, (3) admin_password, (4) new_passwd, and (5) confirm_passwd variables, which are not initialized.
References 7 Total
- http://evuln.com/vulns/73/summary.html
- securityreason.com: 468 third-party-advisory
- securityfocus.com: 20060221 [eVuln] Magic Downloads Unauthorized Data Modification mailing-list
- vupen.com: ADV-2006-0602 vdb-entry
- secunia.com: 18877 third-party-advisory
- exchange.xforce.ibmcloud.com: magicdownloads-settings-access(24615) vdb-entry
- securityfocus.com: 16665 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- http://evuln.com/vulns/73/summary.html x_transferred
- securityreason.com: 468 third-party-advisoryx_transferred
- securityfocus.com: 20060221 [eVuln] Magic Downloads Unauthorized Data Modification mailing-listx_transferred
- vupen.com: ADV-2006-0602 vdb-entryx_transferred
- secunia.com: 18877 third-party-advisoryx_transferred
- exchange.xforce.ibmcloud.com: magicdownloads-settings-access(24615) vdb-entryx_transferred
- securityfocus.com: 16665 vdb-entryx_transferred