Описание
Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."
Ссылки
- PatchVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.30 (включая)
Одно из
cpe:2.3:a:surf-net:asp_forum:*:*:*:*:*:*:*:*
cpe:2.3:a:surf-net:asp_forum:2.20:*:*:*:*:*:*:*
EPSS
Процентиль: 76%
0.00933
Низкий
10 Critical
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."
EPSS
Процентиль: 76%
0.00933
Низкий
10 Critical
CVSS2
Дефекты
NVD-CWE-Other