_RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserName, and (3) cUserID.
References
Configurations
Information
Published : 2008-06-12 05:21
Updated : 2017-09-28 18:31
NVD link : CVE-2008-2682
Mitre link : CVE-2008-2682
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
realm_project
- realm_cms