PT-2007-4899 · Phptraffica · Phptraffica

Published

2007-07-10

·

Updated

2018-10-15

·

CVE-2007-3647

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions phpTrafficA versions 1.4.3 and earlier
Description The issue allows remote attackers to bypass authentication and obtain administrative access. This is achieved by manipulating the username cookie.
Recommendations For phpTrafficA versions 1.4.3 and earlier, as a temporary workaround, consider restricting access to the isloggedin function in Php/login.inc.php until a patch is available. Avoid setting the username cookie to "traffic" to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3647

Affected Products

Phptraffica