PT-2009-6172 · Unknown · Arcade Trade Script

Publicado

2009-11-18

·

Atualizado

2017-09-19

·

CVE-2009-3966

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Arcade Trade Script version 1.0
Description The issue allows remote attackers to bypass authentication and gain administrative access. This is achieved by setting the adminLoggedIn cookie to true, effectively granting unauthorized users administrative privileges.
Recommendations For Arcade Trade Script version 1.0, as a temporary workaround, consider implementing proper cookie validation to prevent unauthorized access until a patch is available. Restrict access to administrative functions to minimize the risk of exploitation. Avoid relying solely on client-side cookie settings for authentication.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-3966

Produtos afetados

Arcade Trade Script