_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserName, and (3) cUserID.
References
Configurations
History
No history.
Information
Published : 2008-06-12 12:21
Updated : 2024-02-04 17:33
NVD link : CVE-2008-2682
Mitre link : CVE-2008-2682
CVE.ORG link : CVE-2008-2682
JSON object : View
Products Affected
realm_project
- realm_cms
CWE
CWE-264
Permissions, Privileges, and Access Controls