vendor:
Tlnews
by:
X0r - EvolutionTeaM
8.8
CVSS
HIGH
Admin Login Bypass
287
CWE
Product Name: Tlnews
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: NO
Related CWE: N/A
CPE: a:easy-script:tlnews
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Tlnews 2.2 Admin Login Bypass (via Cookie)
A vulnerability in Tlnews 2.2 allows an attacker to bypass the admin login by setting a cookie with the value 'tlNews_login=admin; content=admin; path=/'
Mitigation:
Ensure that authentication credentials are properly validated and that the application is not vulnerable to cookie manipulation.