PT-2009-2497 · Rpg · Rpg.Board

Stack

·

Published

2009-08-21

·

Updated

2017-09-29

·

CVE-2008-7028

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RPG.Board versions 0.8 Beta2 and earlier
Description The issue allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a certain value.
Recommendations For RPG.Board versions 0.8 Beta2 and earlier, consider restricting access to sensitive areas of the application until a patch is available. As a temporary workaround, avoid using the keep4u cookie or restrict its modification to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7028

Affected Products

Rpg.Board