cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:30
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/24845 - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/archive/1/465386/100/100/threaded - | |
References | () http://www.umich.edu/~umweb/software/cosign/cosign-vuln-2007-002.txt - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2007/1359 - |
Information
Published : 2007-04-25 15:19
Updated : 2024-11-21 00:30
NVD link : CVE-2007-2233
Mitre link : CVE-2007-2233
CVE.ORG link : CVE-2007-2233
JSON object : View
Products Affected
cosign
- cosign
CWE