SendCard v.3.4.0 Unautorized Administrative Access Security Vulnerability

Description
All administrative script on wrong or no authentication return 302 and try to redirect the user to login panel. But the scripts does not return and continue to output the unauthorized content.

Confirmed in version 3.4.0. Other versions may also be affected.

Impact
The remote attacker can have administrative access and inject php code in config.php through admin/setup.php script.

References
Original Advisory
Product Homepage

View entire list of over 400 known Web Application Vulnerabilities and the specific technologies which they target. See Web Vulnerabilities in popular applications such as: WordPress, Tiki Wiki, PHPNuke, PHPMyAdmin, phpBB, Mambo, PHP-Fusion, Mantis, Invision Power Board

Get latest new web vulnerabilities via RSS