CVE-2006-3772

PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass security restrictions and obtain administrative privileges by modifying the logincookie[user] setting in the login cookie.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php-post:php-post:0.21:*:*:*:*:*:*:*
cpe:2.3:a:php-post:php-post:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2006-07-24 12:19

Updated : 2024-02-04 16:52


NVD link : CVE-2006-3772

Mitre link : CVE-2006-3772

CVE.ORG link : CVE-2006-3772


JSON object : View

Products Affected

php-post

  • php-post