Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2003-0589

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2003-0589
Last Modified 05 Sep 2008 04:34:43
Published 18 Aug 2003 12:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2003-0589

Summary

admin.php in Digi-ads 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.

Vulnerable Systems

Application

  • Digi-fx Digi-news 1.1


References

BUGTRAQ - 20030716 Digi-news and Digi-ads version 1.1 admin access without password


Last Updated: 27 May 2016 10:37:58