The PHP administration script in popper_mod 1.2.1 and earlier relies on Apache .htaccess authentication, which allows remote attackers to gain privileges if the script is not appropriately configured by the administrator.
| Software | From | Fixed in |
|---|---|---|
| symatec / popper_mod | 1.2.1 | 1.2.1.x |
| symatec / popper_mod | 1.2 | 1.2.x |
| symatec / popper_mod | 1.0 | 1.0.x |