admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2009-08-21T14:00:00

Updated: 2024-08-07T11:49:02.500Z

Reserved: 2009-08-21T00:00:00

Link: CVE-2008-7024

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-08-21T14:30:00.563

Modified: 2018-10-11T20:58:03.503

Link: CVE-2008-7024

cve-icon Redhat

No data.