vendor:
RoseOnlineCMS
by:
cr4wl3r
7.5
CVSS
HIGH
Remote Login Bypass
287
CWE
Product Name: RoseOnlineCMS
Affected Version From: <= 3 B1
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2010
RoseOnlineCMS <= 3 B1 Remote Login Bypass Exploit
The RoseOnlineCMS version <= 3 B1 is vulnerable to a remote login bypass exploit. This exploit works only when the magic_quotes_gpc setting is turned off.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a newer version of RoseOnlineCMS that has the necessary patches.