PT-2009-2326 · .Net · Absolute Podcast .Net

Hakxer

·

Published

2009-07-14

·

Updated

2017-09-29

·

CVE-2008-6857

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Absolute Podcast .NET version 1.0
Description: The issue allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.
Recommendations: For Absolute Podcast .NET version 1.0, update the cookie handling mechanism to prevent unauthorized access. As a temporary workaround, consider implementing additional authentication checks to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6857

Affected Products

Absolute Podcast .Net