2 results (0.002 seconds)

CVSS: 9.8EPSS: 1%CPEs: 6EXPL: 2

21 Aug 2009 — Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1. Libra File Manager 1.18 y versiones anteriores permite a atacantes remotos eludir la autenticación y obtener privilegios mediante el establecimiento de las cookies "user" y "pass" a 1. • https://www.exploit-db.com/exploits/6579 • CWE-287: Improper Authentication •

CVSS: 9.1EPSS: 2%CPEs: 6EXPL: 3

29 Sep 2008 — fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string. El módulo fileadmin.php en Libra File Manager (también conocido como Libra PHP File Manager) v1.18 y anteriores permite a atacantes remotos evitar la autenticación, leer ficheros arbitrarios, modificar ficheros arbitrarios y lis... • https://www.exploit-db.com/exploits/6567 • CWE-287: Improper Authentication •