Vulnerabilities > CVE-2002-0097 - Unspecified vulnerability in Geeklog 1.3

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
geeklog
nessus

Summary

Geeklog 1.3 allows remote attackers to hijack user accounts, including the administrator account, by modifying the UID of a user's permanent cookie to the target account.

Vulnerable Configurations

Part Description Count
Application
Geeklog
1

Nessus

NASL familyCGI abuses
NASL idGEEKLOG_ADMIN_ACCESS.NASL
descriptionThe remote server is running a version of Geeklog affected by various vulnerabilities, including SQL injection, arbitrary file upload, privilege escalation, etc.
last seen2020-06-01
modified2020-06-02
plugin id11670
published2003-05-29
reporterThis script is Copyright (C) 2003-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11670
titleGeeklog <= 1.3.7sr1 Multiple Vulnerabilities (SQLi, XSS, Priv Esc)