Security Advisory

CVE-2008-6664

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-04-08 10:00:00
Last updated 2024-08-07 11:41:58
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.