[] NeoSense

Phil's Bookmark Script - 'admin.php' Authentication Bypass

Author: alp_eren@ayyildiz.org
type: webapps
platform: php
port: 
date_added: 2006-05-08 
date_updated: 2013-08-25 
verified: 1 
codes: OSVDB-25681 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/17878/info

Phil's Bookmark script is prone to an authentication-bypass vulnerability. The issue occurs because the affected script fails to prompt for authentication credentials.

An attacker can exploit this issue to bypass authentication and gain admin access to the affected application. This could aid in further attacks on the affected computer.

http://www.example.com/bookmarks/admin.php?edit=1