PT-2009-1767 · Acc · Acc Real Estate

Hakxer

·

Published

2009-02-26

·

Updated

2017-09-29

·

CVE-2008-6293

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Acc Real Estate version 4.0
Description: The issue allows remote attackers to bypass authentication and gain administrative access. This is achieved by setting the username cookie to "admin".
Recommendations: For Acc Real Estate version 4.0, consider temporarily disabling the use of username cookie or restrict access to administrative areas until a patch is available. Additionally, review and modify the authentication mechanism to prevent such bypasses.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6293

Affected Products

Acc Real Estate