Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    20 Nov 2024, 23:36
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://marc.info/?l=bugtraq&m=99834088223352&w=2 - | |
| References | () http://www.securityfocus.com/bid/3210 - Patch, Vendor Advisory | |
| References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/7011 - | 
Information
                Published : 2001-08-31 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2001-0972
Mitre link : CVE-2001-0972
CVE.ORG link : CVE-2001-0972
JSON object : View
Products Affected
                surf-net
- asp_forum
CWE
                