Vulnerabilities > CVE-2007-2081 - Authentication Bypass vulnerability in MyBlog Settings.PHP

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
myblog
exploit available

Summary

MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication requirements via the admin cookie parameter to certain admin files, as demonstrated by admin/settings.php.

Vulnerable Configurations

Part Description Count
Application
Myblog
1

Exploit-Db

descriptionMyBlog 0.9.8 Settings.PHP Authentication Bypass Vulnerability. CVE-2007-2081. Webapps exploit for php platform
idEDB-ID:29864
last seen2016-02-03
modified2007-04-16
published2007-04-16
reporterBlackHawk
sourcehttps://www.exploit-db.com/download/29864/
titleMyBlog 0.9.8 Settings.PHP Authentication Bypass Vulnerability