HIGH · 7.5

CVE-2008-6001

index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpusuario cookie composed of an initial sysop: string, an arbitrary password field,...

Vulnerability Description

index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpusuario cookie composed of an initial sysop: string, an arbitrary password field, and a final :sysop:0 string.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
AdnforumAdnforum<= 1.0b

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-6001?

CVE-2008-6001 is a vulnerability with a CVSS score of 7.5 (HIGH). index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpusuario cookie composed of an initial sysop: string, an arbitrary password field,...

How severe is CVE-2008-6001?

CVE-2008-6001 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-6001?

Check the references section above for vendor advisories and patch information. Affected products include: Adnforum Adnforum.