MEDIUM · 5.0

CVE-2006-3837

delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie's value, which makes it easier for attackers to steal the cookie and obta...

Vulnerability Description

delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie's value, which makes it easier for attackers to steal the cookie and obtain the administrator's password hash after logout.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Professional Home Page ToolsProfessional Home Page Tools GuestbookAll versions

References

FAQ

What is CVE-2006-3837?

CVE-2006-3837 is a vulnerability with a CVSS score of 5.0 (MEDIUM). delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie's value, which makes it easier for attackers to steal the cookie and obta...

How severe is CVE-2006-3837?

CVE-2006-3837 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-3837?

Check the references section above for vendor advisories and patch information. Affected products include: Professional Home Page Tools Professional Home Page Tools Guestbook.