9.3
CVSSv2

CVE-2007-2822

Published: 22/05/2007 Updated: 11/10/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

TutorialCMS 1.01 and previous versions, when register_globals is enabled, allows remote malicious users to bypass authentication via the (1) loggedIn and (2) activated parameters to (a) login.php, (b) headerLinks.php, (c) submit1.php, (d) myFav.php, and (e) userCP.php.

Vulnerable Product Search on Vulmon Subscribe to Product

wavelink media tutorialcms

Exploits

################################################################################# # # # TutorialCMS <= 101 Authentication Bypass # # # # Discovered by: Silentz # # Payload: Authentication Bypass # # Website: wwww4ck1ngcom # # # # Vulnerability: # # # # Variables $logge ...