WHMCS Insecure Cookie Authentication Bypass Vulnerability
BID:57145
Info
WHMCS Insecure Cookie Authentication Bypass Vulnerability
| Bugtraq ID: | 57145 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 31 2012 12:00AM |
| Updated: | Dec 31 2012 12:00AM |
| Credit: | Agd_Scorp |
| Vulnerable: |
WHMCS WHMCS 5.1 WHMCS WHMCS 5.0 |
| Not Vulnerable: | |
Discussion
WHMCS Insecure Cookie Authentication Bypass Vulnerability
WHMCS is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
Attackers can exploit this vulnerability to gain administrative access to the affected application, which may aid in further attacks.
WHMCS 5.0 and 5.1 are vulnerable; other versions may also be affected.
WHMCS is prone to an authentication-bypass vulnerability because it fails to adequately verify user-supplied input used for cookie-based authentication.
Attackers can exploit this vulnerability to gain administrative access to the affected application, which may aid in further attacks.
WHMCS 5.0 and 5.1 are vulnerable; other versions may also be affected.