PT-2008-5994 · Aflog · Aflog
Joss
·
Published
2008-10-29
·
Updated
2017-09-29
·
CVE-2008-4784
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
aflog version 1.01
Description
The issue allows remote attackers to bypass authentication and gain administrative access. This can be achieved by setting the
aflog auth a cookie to "A" or "O" in several API endpoints, including "edit delete.php", "edit cat.php", "edit lock.php", and "edit form.php".Recommendations
For aflog version 1.01, as a temporary workaround, consider restricting access to the "edit delete.php", "edit cat.php", "edit lock.php", and "edit form.php" endpoints until a patch is available. Avoid using the
aflog auth a cookie or restrict its value to prevent unauthorized access.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aflog