7.5
CVSSv2

CVE-2006-0844

Published: 22/02/2006 Updated: 20/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote malicious users to bypass login authentication, probably by setting the blogAdmin cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

leif m. wright web blog 3.5

Exploits

Leif M Wright's Blog version 35 is susceptible to information disclosure, authentication bypass, code execution, and cross site scripting flaws Exploit details provided ...