7.5
CVSSv2

CVE-2008-6919

Published: 10/08/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

profileedit.php TaskDriver 1.3 and previous versions allows remote malicious users to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."

Vulnerable Product Search on Vulmon Subscribe to Product

taskdriver taskdriver

taskdriver taskdriver 1.2

Exploits

<?php /* $Id: taskdriver-13php,v 01 2008/12/03 04:04:28 cOndemned Exp $ TaskDriver <= 13 Remote Change Admin Password Exploit Bug found && Exploited by cOndemned Download: wwwtaskdrivercom/downtrack/indexphp?down=2 Description: This exploit uses insecure cookie handling flaw in order to compromisse ...