CVE-2012-4974

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
12/12/2012
Last modified:
28/12/2012

Description

Layton Helpbox 4.4.0 allows remote authenticated users to change the login context and gain privileges via a modified (1) loggedinenduser, (2) loggedinendusername, (3) loggedinuserusergroup, (4) loggedinuser, or (5) loggedinusername cookie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:laytontechnology:helpbox:4.4.0:*:*:*:*:*:*:*