10
CVSSv2

CVE-2002-1428

Published: 11/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

index.php in dotProject 0.2.1.5 allows remote malicious users to bypass authentication via a cookie or URL with the user_cookie parameter set to 1.

Vulnerable Product Search on Vulmon Subscribe to Product

dotproject dotproject 0.2.1.5

Exploits

source: wwwsecurityfocuscom/bid/5347/info dotproject is prone to an issue which may allow remote attackers to bypass authentication and gain administrative access to the software This may be accomplished by submitting a maliciously crafted 'user_cookie' value either manually or via manipulation of URI parameters This problem is due t ...