PT-2004-2746 · Unknown · News Manager Lite

Published

2004-03-20

·

Updated

2017-07-11

·

CVE-2004-1847

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions News Manager Lite version 2.5
Description The issue allows remote attackers to bypass authentication and gain administrator privileges. This is achieved by setting the ADMIN parameter in the NEWS LOGIN cookie.
Recommendations For News Manager Lite version 2.5, consider removing or restricting the ADMIN parameter in the NEWS LOGIN cookie to prevent unauthorized access until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1847

Affected Products

News Manager Lite