Description
|
|
Two vulnerabilities were identified in DownFile, which could be exploited by attackers to gain unauthorized access or conduct cross site scripting attacks.
The first issue is due to an error in the authentication procedure, which could be exploited by remote attackers to gain unauthorized administrative access to the application.
The second flaw is due to input validation errors in the "index.php", "email.php", "del.php", and "add_form.php" scripts that do not properly filter a specially crafted "id" parameter.
|