admin/default.asp in Orion-Blog 2.0 allows remote malicious users to bypass authentication controls and gain privileges via a direct URL request for admin/AdminBlogNewsEdit.asp.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
orion-blog orion-blog 2.0 |