CVE-2008-6664 Information

Description

action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.

Reference

http://www.securityfocus.com/bid/29725 http://www.shnews.de/change-log https://exchange.xforce.ibmcloud.com/vulnerabilities/43123 https://www.exploit-db.com/exploits/5829

Share on: