MEDIUM
Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting
Published Jan 10, 2008
6.4
MEDIUMCVSS 2.0
EPSS 2.13%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.