PT-2009-4043 · Agtc · Agtc Myshop

Mr.Tro0Oqy

·

Published

2009-05-06

·

Updated

2017-09-29

·

CVE-2009-1549

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: AGTC MyShop version 3.2b
Description: The issue allows remote attackers to bypass authentication and obtain administrative access by setting the log accept cookie to "correcto."
Recommendations: For AGTC MyShop version 3.2b, consider restricting access to administrative functions until a patch is available. As a temporary workaround, avoid using the log accept cookie or restrict its modification to prevent unauthorized access.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1549

Affected Products

Agtc Myshop