Vulnerabilities > CVE-2014-9006 - Credentials Management vulnerability in Monstra

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
monstra
CWE-255

Summary

Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attackers to conduct brute force login attacks by deleting the login_attempts cookie or setting it to certain values.

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/129082/monstra-bypass.txt
idPACKETSTORM:129082
last seen2016-12-05
published2014-11-12
reporterPaulos Yibelo
sourcehttps://packetstormsecurity.com/files/129082/Monstra-3.0.1-Bruteforce-Mitigation-Bypass.html
titleMonstra 3.0.1 Bruteforce Mitigation Bypass