HIGH
newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cookie to "xY1zZoPQ"
Published May 30, 2006
7.5
HIGHCVSS 2.0
EPSS 3.63%
Description
newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cookie to "xY1zZoPQ".
Affected products
No data.
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://secunia.com/advisories/20294 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securityreason.com/securityalert/974 third-party-advisoryx_refsource_SREASON
- http://www.bugreport.ir/index_62.htm x_refsource_MISCExploit
- http://www.kapda.ir/advisory-332.html x_refsource_MISCVendor Advisory
- http://www.securityfocus.com/archive/1/435019/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/500407/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.vupen.com/english/advisories/2006/1993 vdb-entryx_refsource_VUPENVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-2635 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26698 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/20294 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://securityreason.com/securityalert/974 | third-party-advisoryx_refsource_SREASON | |
| http://www.bugreport.ir/index_62.htm | x_refsource_MISCExploit | |
| http://www.kapda.ir/advisory-332.html | x_refsource_MISCVendor Advisory | |
| http://www.securityfocus.com/archive/1/435019/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/archive/1/500407/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.vupen.com/english/advisories/2006/1993 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-2635 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/26698 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 30, 2006
Updated Aug 7, 2024
Reserved May 30, 2006
Link CVE-2006-2636
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-2635 Assigner mitre
Published May 30, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-2635