PT-2006-1710 · Hinton Design · Phpht Topsites
Aliaksandr Hartsuyeu
·
Published
2006-02-13
·
Updated
2018-10-19
·
CVE-2006-0654
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Hinton Design phpht Topsites version 1.3
Description
The issue concerns the
check.php file, which fails to validate passwords when using cookies. This allows remote attackers to bypass authentication by using unspecified cookies.Recommendations
For Hinton Design phpht Topsites version 1.3, consider disabling the use of cookies for authentication until a patch is available. Restrict access to the
check.php file to minimize the risk of exploitation. Avoid using cookies for authentication in the affected version until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpht Topsites