vendor:
Entertainment Portal
by:
G4N0K
7.5
CVSS
HIGH
Insecure Cookie Handling
264
CWE
Product Name: Entertainment Portal
Affected Version From: 2
Affected Version To: 2
Patch Exists: YES
Related CWE: N/A
CPE: a:turnkey_forms:entertainment_portal
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Entertainment Portal v2.0 Insecure Cookie Handling Vulnerability
A vulnerability exists in Entertainment Portal v2.0 which allows an attacker to gain administrative access by setting a cookie. An attacker can exploit this issue by setting the 'adminLogged' cookie to 'Administrator' and then accessing the admin panel.
Mitigation:
The vendor has released a patch to address this issue. It is advised to upgrade to the latest version of the software.