Vulnerabilities > CVE-2004-1847 - Multiple vulnerability in Expinion.net News Manager Lite

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
expinion-net
exploit available

Summary

News Manager Lite 2.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN parameter in the NEWS_LOGIN cookie.

Vulnerable Configurations

Part Description Count
Application
Expinion.Net
1

Exploit-Db

descriptionExpinion.net News Manager Lite 2.5 NEWS_LOGIN Cookie ADMIN Parameter Manipulation Admin Authentication Bypass. CVE-2004-1847. Webapps exploit for asp platform
idEDB-ID:23863
last seen2016-02-02
modified2004-03-20
published2004-03-20
reporterManuel Lopez
sourcehttps://www.exploit-db.com/download/23863/
titleExpinion.net News Manager Lite 2.5 NEWS_LOGIN Cookie ADMIN Parameter Manipulation Admin Authentication Bypass