>> Ampache Register Globals Session Handling Information Disclosure Vulnerability
Title : Ampache Register Globals Session Handling Information Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2006-4236 CVE ID : CVE-2006-5668
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-29
Technical Description
A vulnerability has been identified in Ampache, which could be exploited by malicious users to bypass security restrictions. This flaw is due to an error within session management when the "register_globals" feature is enabled, which could be exploited by malicious users to obtain a guest level access to a vulnerable instance allowing them to gain unauthorized access to certain catalogs.