7.5
CVSSv2

CVE-2009-0461

Published: 10/02/2009 Updated: 19/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Whole Hog Password Protect: Enhanced 1.x allows remote malicious users to bypass authentication and obtain administrative access via an integer value in the adminid cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

wholehogsoftware password protect 1.0

Exploits

########################################################################### [+] WholeHogSoftware Password Protect Insecure Cookie Handling Vulnerability [+] Script :Password Protect [+] Site :wholehogsoftwarecom [+] Detay :wwwwholehogsoftwarecom/indexphp/page/password_protect_enhanced [+] Discovered By Mountassif Moad ...
########################################################################### [+] WholeHogSoftware Ware Support Insecure Cookie Handling Vulnerability [+] Script :Ware Support [+] Site :wholehogsoftwarecom [+] Detay :wholehogsoftwarecom/indexphp/page/ware_support [+] Discovered By Mountassif Moad [+] wwwv4 ...