PT-2006-1661 · Hinton Design · Hinton Design Phphg Guestbook
Aliaksandr Hartsuyeu
·
Published
2006-02-08
·
Updated
2018-10-19
·
CVE-2006-0604
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Hinton Design phphg Guestbook version 1.2
Description
The issue concerns the authentication mechanism in the guestbook application. Specifically, the
check.php file does not properly verify the user password when authentication is performed via cookies. This oversight allows remote attackers to gain unauthorized access to the system.Recommendations
For Hinton Design phphg Guestbook version 1.2, as a temporary workaround, consider disabling cookie-based authentication until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hinton Design Phphg Guestbook