Lucene search

K
cveMitreCVE-2008-6856
HistoryJul 14, 2009 - 2:30 p.m.

CVE-2008-6856

2009-07-1414:30:00
CWE-287
mitre
web.nvd.nist.gov
22
cve
xigla software
absolute news manager
.net
authentication
bypass
remote attackers
cookie
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.019

Percentile

88.4%

Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

Affected configurations

Nvd
Node
xiglaabsolute_news_manager.netMatch5.1
VendorProductVersionCPE
xiglaabsolute_news_manager.net5.1cpe:2.3:a:xigla:absolute_news_manager.net:5.1:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.4

Confidence

Low

EPSS

0.019

Percentile

88.4%

Related for CVE-2008-6856