CVE-2004-2443 Information
Feb 14, 2021
cve
Description
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password which is compared against the logged session variable by the logged_on function in application.php.
Reference
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0226.html http://securitytracker.com/id?1010651 http://www.osvdb.org/7724 http://www.securityfocus.com/bid/10670 https://exchange.xforce.ibmcloud.com/vulnerabilities/16622
Share on: