CVE-2009-2025

admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dutchmonkey:dm_filemanager:3.9.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2009-06-09 19:30

Updated : 2024-02-04 17:33


NVD link : CVE-2009-2025

Mitre link : CVE-2009-2025

CVE.ORG link : CVE-2009-2025


JSON object : View

Products Affected

dutchmonkey

  • dm_filemanager
CWE
CWE-264

Permissions, Privileges, and Access Controls