PT-2003-1845 · Attila · Attilaphp
Published
2003-09-06
·
Updated
2008-09-05
·
CVE-2003-0752
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
AttilaPHP versions 3.0 and earlier
Description:
The issue allows remote attackers to bypass authentication. This is achieved by modifying the
cook id parameter.Recommendations:
For AttilaPHP versions 3.0 and earlier, consider restricting access to the global.php3 file until a patch is available. As a temporary workaround, avoid using the
cook id parameter in the affected API endpoint until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Attilaphp