vendor:
Web Slider
by:
t0pP8uZz
7.5
CVSS
HIGH
Insecure Cookie/Authentication Handling
287
CWE
Product Name: Web Slider
Affected Version From: 0.1
Affected Version To: 0.6
Patch Exists: NO
Related CWE:
CPE: a:webslider_project:webslider:0.6
Platforms Tested:
2008
Web Slider <= 0.6 Insecure Cookie/Authentication Handling
The Web Slider script version 0.6 and prior suffers from insecure cookie handling. When an admin logs in successfully, a cookie is created without containing any password or other authentication data. By creating a specific cookie, an attacker can impersonate an admin and gain unauthorized access to restricted areas.
Mitigation:
The vendor has not been notified. To mitigate this vulnerability, it is recommended to update to a patched version or discontinue the use of the Web Slider script.