7.5
CVSSv2

CVE-2007-2081

Published: 18/04/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

MyBlog 0.9.8 and previous versions allows remote malicious users to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php.

Vulnerable Product Search on Vulmon Subscribe to Product

myblog myblog

Exploits

source: wwwsecurityfocuscom/bid/23521/info MyBlog is prone to an authentication-bypass vulnerability Attackers can exploit this issue to bypass the authentication mechanism and then access or overwrite files with arbitrary PHP script code Script code added to certain files are later included for execution, allowing the attacker to expl ...