CVE-2008-4784 Information
Feb 14, 2021
cve
Description
aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to \A\ or \O\ in (1) edit_delete.php (2) edit_cat.php (3) edit_lock.php and (4) edit_form.php.
Reference
http://securityreason.com/securityalert/4524 http://www.securityfocus.com/bid/31894 https://exchange.xforce.ibmcloud.com/vulnerabilities/46083 https://www.exploit-db.com/exploits/6818
Share on: