7.5
CVSSv2

CVE-2006-2636

Published: 30/05/2006 Updated: 18/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

newsadmin.asp in Katy Whitton NewsCMSLite allows remote malicious users to bypass authentication and gain administrative access by setting the loggedIn cookie to "xY1zZoPQ".

Vulnerable Product Search on Vulmon Subscribe to Product

katy whitton newscmslite

Exploits

source: wwwsecurityfocuscom/bid/33467/info NewsCMSLite is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication Attackers can exploit this vulnerability to gain unauthorized access to the affected application, which may aid in further attacks jav ...