phpProfiles prior to 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
phpprofiles phpprofiles 2.1.0 |