Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.
References
Configurations
Information
Published : 2008-10-23 10:17
Updated : 2017-09-28 18:32
NVD link : CVE-2008-4714
Mitre link : CVE-2008-4714
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
atomic_photo_album
- atomic_photo_album