7.5
CVSSv2

CVE-2008-4622

Published: 21/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote malicious users to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1.

Vulnerable Product Search on Vulmon Subscribe to Product

phpfastnews phpfastnews 1.0.0

Exploits

################################################# ## Qabandi iqa[at]hotmailfr ## ## from Kuwait ## ################################################# \\ phpFastNews // Insecure cookie handling \\ // Go to any website that has the script installed \\ type the following code into the Adress Bar // \\ javascript:documentcookie = "fn ...