The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) username, (2) password, (3) usertheme, and (4) userlang cookies for unauthorized users, which has unknown impact and remote attack vectors.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-06-26T23:00:00

Updated: 2024-08-07T14:14:12.937Z

Reserved: 2007-06-26T00:00:00

Link: CVE-2007-3420

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-06-26T23:30:00.000

Modified: 2008-11-15T06:52:32.627

Link: CVE-2007-3420

cve-icon Redhat

No data.