PT-2002-1542 · Alguest · Alguest
Publicado
2002-06-11
·
Atualizado
2008-09-05
·
CVE-2002-0491
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AlGuest version 1.0
Description
The issue allows remote attackers to bypass authentication and gain privileges by setting the
admin cookie to an arbitrary value. This is due to the admin.php file in AlGuest checking for the existence of the admin cookie to authenticate the administrator.Recommendations
For AlGuest version 1.0, consider disabling the
admin.php file or restricting access to it until a proper authentication mechanism is implemented to prevent arbitrary admin cookie values from being set.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alguest