6.8
CVSSv2

CVE-2009-1283

Published: 09/04/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

glFusion prior to 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote malicious users to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this can be leveraged with a separate SQL injection vulnerability to steal hashes.

Vulnerable Product Search on Vulmon Subscribe to Product

glfusion glfusion 1.1.0

glfusion glfusion 1.0.0

glfusion glfusion 1.0.1

glfusion glfusion 1.0.2

glfusion glfusion 1.1.1

glfusion glfusion

Exploits

<?php /* glFusion <= 112 COM_applyFilter()/cookies remote blind sql injection exploit by Nine:Situations:Group::bookoo our site: retrogodaltervistaorg/ software site: wwwglfusionorg/ google dork: "Page created in" "seconds by glFusion" +RSS Found another vector of injection in ...