UNAK-CMS - Cookie Authentication Bypass

EDB-ID:

32402

CVE:

N/A


Author:

Ciph3r

Type:

webapps


Platform:

PHP

Date:

2008-09-22


source: https://www.securityfocus.com/bid/31301/info

UNAK-CMS is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.

An attacker can exploit this vulnerability to gain administrative access to the affected application; other attacks are also possible. 

javascript:document.cookie = "unak_lang=1; path=/";