CVE-2009-4091

comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments via the (1) edit or (2) del action.
Configurations

Configuration 1 (hide)

cpe:2.3:a:simplog:simplog:0.9.3.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-11-29 13:07

Updated : 2024-02-28 11:21


NVD link : CVE-2009-4091

Mitre link : CVE-2009-4091

CVE.ORG link : CVE-2009-4091


JSON object : View

Products Affected

simplog

  • simplog
CWE
CWE-264

Permissions, Privileges, and Access Controls