7.5
CVSSv2

CVE-2007-2232

Published: 25/04/2007 Updated: 16/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The CHECK command in Cosign 2.0.1 and previous versions allows remote malicious users to bypass authentication requirements via CR (\r) sequences in the cosign cookie parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

cosign cosign 0.7.0

cosign cosign 1.7

cosign cosign 1.8

cosign cosign 1.5

cosign cosign 1.6

cosign cosign 0.8.0

cosign cosign 0.9.0

cosign cosign 1.8.5

cosign cosign 1.9

cosign cosign 1.0

cosign cosign 1.1

cosign cosign 2.0.1

Exploits

source: wwwsecurityfocuscom/bid/23422/info The 'cosign' application is prone to an authentication-bypass vulnerability because it fails to adequately sanitize user-supplied input An attacker can exploit this issue to gain unauthorized access to services hosted on an affected computer Versions prior to 194b and 202a are vulnerable ...