Total vulnerabilities in the database
The documentation for AJ-Fork 167 implies that users should set permissions for users.db.php to 777, which allows local users to execute arbitrary PHP code and gain privileges as the administrator.
Software | From | Fixed in |
---|---|---|
aj-fork / aj-fork | 167 | 167.x |
cutephp / cutenews | 1.3.6 | 1.3.6.x |
cutephp / cutenews | 1.3.2 | 1.3.2.x |
cutephp / cutenews | 0.88 | 0.88.x |
cutephp / cutenews | 1.3 | 1.3.x |
cutephp / cutenews | 1.3.1 | 1.3.1.x |