Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.
References
Configurations
History
No history.
Information
Published : 2008-10-23 17:17
Updated : 2025-04-09 00:30
NVD link : CVE-2008-4714
Mitre link : CVE-2008-4714
CVE.ORG link : CVE-2008-4714
JSON object : View
Products Affected
atomic_photo_album
- atomic_photo_album
CWE
CWE-287
Improper Authentication