cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.
References
Link | Resource |
---|---|
http://secunia.com/advisories/24845 | Patch Vendor Advisory |
http://www.securityfocus.com/archive/1/465386/100/100/threaded | |
http://www.umich.edu/~umweb/software/cosign/cosign-vuln-2007-002.txt | Vendor Advisory |
http://www.vupen.com/english/advisories/2007/1359 |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2007-04-25 15:19
Updated : 2024-02-28 11:01
NVD link : CVE-2007-2233
Mitre link : CVE-2007-2233
CVE.ORG link : CVE-2007-2233
JSON object : View
Products Affected
cosign
- cosign
CWE