Vulnerability Description
newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cookie to "xY1zZoPQ".
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Katy Whitton | Newscmslite | All versions |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/20294Vendor Advisory
- http://securityreason.com/securityalert/974
- http://www.bugreport.ir/index_62.htmExploit
- http://www.kapda.ir/advisory-332.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/435019/100/0/threaded
- http://www.securityfocus.com/archive/1/500407/100/0/threaded
- http://www.vupen.com/english/advisories/2006/1993Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26698
- http://secunia.com/advisories/20294Vendor Advisory
- http://securityreason.com/securityalert/974
- http://www.bugreport.ir/index_62.htmExploit
- http://www.kapda.ir/advisory-332.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/435019/100/0/threaded
- http://www.securityfocus.com/archive/1/500407/100/0/threaded
- http://www.vupen.com/english/advisories/2006/1993Vendor Advisory
FAQ
What is CVE-2006-2636?
CVE-2006-2636 is a vulnerability with a CVSS score of 7.5 (HIGH). newsadmin.asp in Katy Whitton NewsCMSLite allows remote attackers to bypass authentication and gain administrative access by setting the loggedIn cookie to "xY1zZoPQ".
How severe is CVE-2006-2636?
CVE-2006-2636 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-2636?
Check the references section above for vendor advisories and patch information. Affected products include: Katy Whitton Newscmslite.