phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.
References
Configurations
Information
Published : 2008-04-27 11:05
Updated : 2017-09-28 18:30
NVD link : CVE-2008-1971
Mitre link : CVE-2008-1971
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
phphq
- phshoutbox_final