vendor:
Shorty
by:
milw0rm.com
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: Shorty
Affected Version From: Shorty v0.7.1 Beta
Affected Version To: Shorty v0.7.1 Beta
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
Shorty v0.7.1 Beta Authentication Bypass
A vulnerability exists in Shorty v0.7.1 Beta, which allows an attacker to bypass authentication by setting the 'snickerdoodle' cookie to 'polarbears'. This can be done by writing 'javascript:document.cookie="snickerdoodle=polarbears";' in the URL or by creating the cookie with a Firefox extension.
Mitigation:
Upgrade to the latest version of Shorty v0.7.1 Beta.