Great Reviews!Need help setting up your website, installing Apache, PHP, MySQL, or PhpNuke?Need help customizing or designing scripts?Please contact me via the Contact Us option for further details and pricing.
DESCRIPTION: Lucas Bartholemy has reported a vulnerability in WebGUI, which can be exploited by malicious users to delete assets.
The vulnerability is caused due to the "www_purgeList()" method not correctly checking the permissions of a user when deleting an asset. The vulnerability is reported in all 7.x versions prior to 7.3.8.
SOLUTION: Update to version 7.3.8.
PROVIDED AND/OR DISCOVERED BY: The vendor credits Lucas Bartholemy.
ORIGINAL ADVISORY:
http://www.plainblack.com/getwebgui/advisories/security-defect-discovered-in-7.x-versions
http://sourceforge.net/project/shownotes.php?release_id=481584
Posted on Monday, January 29, 2007 @ 11:56:30 EST by Raven