PT-2007-3423 · Myblog · Myblog
Publicado
2007-04-18
·
Atualizado
2018-10-16
·
CVE-2007-2081
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MyBlog versions 0.9.8 and earlier
Description
The issue allows remote attackers to bypass authentication requirements. This can be achieved via the
admin cookie parameter to certain admin files, such as "admin/settings.php".Recommendations
For MyBlog versions 0.9.8 and earlier, consider restricting access to admin files until a patch is available. As a temporary workaround, avoid using the
admin cookie parameter in sensitive areas of the application.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Myblog