CVE-2008-1904
22.04.2008, 04:41
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attackers to obtain access to the "admin area" via a modified this_cookie cookie.Enginsight
Vendor | Product | Version |
---|---|---|
cicoandcico | ccmail | 𝑥 ≤ 1.0.1 |
cicoandcico | ccmail | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References