Geeklog 1.3 allows remote attackers to hijack user accounts, including the administrator account, by modifying the UID of a user's permanent cookie to the target account.
References
Link | Resource |
---|---|
http://online.securityfocus.com/archive/1/249443 | Vendor Advisory |
http://www.iss.net/security_center/static/7869.php | Patch Vendor Advisory |
http://geeklog.sourceforge.net/index.php?topic=Security | |
http://www.securityfocus.com/bid/3844 |
Configurations
Information
Published : 2002-03-24 21:00
Updated : 2008-09-10 12:11
NVD link : CVE-2002-0097
Mitre link : CVE-2002-0097
JSON object : View
CWE
Products Affected
geeklog
- geeklog