vendor:
News Management System
by:
Virangar Security Team
N/A
CVSS
N/A
Insecure Cookie Handling
CWE
Product Name: News Management System
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
A+ PHP Scripts – News Management System Insecure Cookie Handling Vulnerability
The A+ PHP Scripts - News Management System suffers from insecure cookie handling. When an admin login is successful, the script creates a cookie to show that the user is already logged in. However, the cookie does not contain any password or similar authentication. This allows an attacker to craft an admin cookie and make it look like they are logged in as a legitimate admin.
Mitigation:
Unknown