CVE

CVE-2001-0972

Severity:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/08/2001
Last modified:
11/07/2017

Description

Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:surf-net:asp_forum:*:*:*:*:*:*:*:* 2.30 (including)
cpe:2.3:a:surf-net:asp_forum:2.20:*:*:*:*:*:*:*