vendor:
phpLiterAdmin
by:
High-Tech Bridge SA - Ethical Hacking & Penetration Testing
7.5
CVSS
HIGH
Authentication bypass
287
CWE
Product Name: phpLiterAdmin
Affected Version From: 1.0 RC1
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: cpe:2.3:a:phpliteradmin:phpliteradmin:1.0_rc1:*:*:*:*:*:*:*
Platforms Tested:
2010
Authentication Bypass in phpLiterAdmin
The phpLiterAdmin application is affected by an authentication bypass vulnerability. The issue occurs due to improper sanitization of user-supplied input during authentication. Exploiting this vulnerability allows unauthorized access to any known account by setting specially crafted cookies.
Mitigation:
Upgrade to the most recent version