CVE-2009-2382

admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin cookie to LOGGEDIN.
References
Link Resource
http://osvdb.org/55505 Broken Link Exploit
http://secunia.com/advisories/35660 Broken Link Vendor Advisory
http://www.exploit-db.com/exploits/9053 Exploit Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/51445 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:jay-jayx0r:phpmyblockchecker:1.0.0055:*:*:*:*:*:*:*

History

13 Feb 2024, 17:44

Type Values Removed Values Added
References () http://osvdb.org/55505 - Exploit () http://osvdb.org/55505 - Broken Link, Exploit
References () http://secunia.com/advisories/35660 - Vendor Advisory () http://secunia.com/advisories/35660 - Broken Link, Vendor Advisory
References () http://www.exploit-db.com/exploits/9053 - () http://www.exploit-db.com/exploits/9053 - Exploit, Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/51445 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/51445 - Third Party Advisory, VDB Entry
CVSS v2 : 7.5
v3 : unknown
v2 : 7.5
v3 : 9.8

Information

Published : 2009-07-08 15:30

Updated : 2024-02-13 17:44


NVD link : CVE-2009-2382

Mitre link : CVE-2009-2382

CVE.ORG link : CVE-2009-2382


JSON object : View

Products Affected

jay-jayx0r

  • phpmyblockchecker
CWE
CWE-287

Improper Authentication