PT-2006-1710 · Hinton Design · Phpht Topsites
Aliaksandr Hartsuyeu
·
Publicado
2006-02-13
·
Atualizado
2018-10-19
·
CVE-2006-0654
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Hinton Design phpht Topsites version 1.3
Description
The issue concerns the
check.php file, which fails to validate passwords when using cookies. This allows remote attackers to bypass authentication by using unspecified cookies.Recommendations
For Hinton Design phpht Topsites version 1.3, consider disabling the use of cookies for authentication until a patch is available. Restrict access to the
check.php file to minimize the risk of exploitation. Avoid using cookies for authentication in the affected version until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpht Topsites