Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."
References
| Link | Resource |
|---|---|
| http://www.securityfocus.com/bid/3210 | Patch Vendor Advisory |
| http://marc.info/?l=bugtraq&m=99834088223352&w=2 | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/7011 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2001-08-30 21:00
Updated : 2017-07-10 18:29
NVD link : CVE-2001-0972
Mitre link : CVE-2001-0972
JSON object : View
CWE
Products Affected
surf-net
- asp_forum


