6.5
CVSSv2

CVE-2007-2233

Published: 25/04/2007 Updated: 16/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

cosign-bin/cosign.cgi in Cosign 2.0.2 and previous versions allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.

Vulnerable Product Search on Vulmon Subscribe to Product

cosign cosign 0.7.0

cosign cosign 0.8.0

cosign cosign 1.8

cosign cosign 1.8.5

cosign cosign 1.1

cosign cosign 1.5

cosign cosign 0.9.0

cosign cosign 1.0

cosign cosign 1.9

cosign cosign 2.0.1

cosign cosign 2.0.2

cosign cosign 1.6

cosign cosign 1.7

Exploits

source: wwwsecurityfocuscom/bid/23424/info The 'cosign' application is prone to an authentication-bypass vulnerability because it fails to adequately sanitize user-supplied input An authenticated attacker can exploit this issue to access services hosted on an affected computer by assuming another user's credentials Versions prior to 1 ...