PT-2007-3423 · Myblog · Myblog
Published
2007-04-18
·
Updated
2018-10-16
·
CVE-2007-2081
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MyBlog versions 0.9.8 and earlier
Description
The issue allows remote attackers to bypass authentication requirements. This can be achieved via the
admin cookie parameter to certain admin files, such as "admin/settings.php".Recommendations
For MyBlog versions 0.9.8 and earlier, consider restricting access to admin files until a patch is available. As a temporary workaround, avoid using the
admin cookie parameter in sensitive areas of the application.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Myblog