[] NeoSense

MyGuestBK - Unauthorized Admin Panel Access

Author: Over_G
type: webapps
platform: asp
port: 
date_added: 2002-03-27 
date_updated: 2012-11-03 
verified: 1 
codes: OSVDB-4625 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/7213/info

MyGuestBk has been reported vulnerable to unauthorized Admin Panel Access.

It has been reported that an attacker may access arbitrary MyGuestBK administrative functions through the MyGuestBK administration panel without prior authorization.

http://www.example.com/myguestBk/admin/index.asp
http://www.example.com/myguestBk/admin/delEnt.asp?id=NEWSNUMBER