vendor:
PhpAddEdit
by:
x0r (Evolution Team)
7.5
CVSS
HIGH
Login Bypass
287
CWE
Product Name: PhpAddEdit
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: Yes
Related CWE: N/A
CPE: a:phpaddedit:phpaddedit:1.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
PhpAddEdit 1.3 Login By Pass
PhpAddEdit 1.3 is vulnerable to a login bypass vulnerability. An attacker can bypass the authentication process by setting the 'addedit' cookie to the username of the admin. This can be done by using the following javascript code: javascript:document.cookie = 'addedit=[adminuser]; path=/';
Mitigation:
Upgrade to the latest version of PhpAddEdit 1.3