PT-2009-4043 · Agtc · Agtc Myshop
Mr.Tro0Oqy
·
Published
2009-05-06
·
Updated
2017-09-29
·
CVE-2009-1549
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
AGTC MyShop version 3.2b
Description:
The issue allows remote attackers to bypass authentication and obtain administrative access by setting the
log accept cookie to "correcto."Recommendations:
For AGTC MyShop version 3.2b, consider restricting access to administrative functions until a patch is available. As a temporary workaround, avoid using the
log accept cookie or restrict its modification to prevent unauthorized access.Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Agtc Myshop