PT-2009-1768 · Acc · Acc Statistics

Hakxer

·

Published

2009-02-26

·

Updated

2017-09-29

·

CVE-2008-6294

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Acc Statistics version 1.1
Description: The issue allows remote attackers to bypass authentication and gain administrative access. This is achieved by setting the username cookie cookie to "admin".
Recommendations: For Acc Statistics version 1.1, consider temporarily restricting access to the admin/Index.php page until a patch is available. As a workaround, avoid using the username cookie cookie or restrict its modification to prevent unauthorized access.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6294

Affected Products

Acc Statistics