Vulnerabilities > Pheap

DATE CVE VULNERABILITY TITLE RISK
2007-06-01 CVE-2007-2985 Permissions, Privileges, and Access Controls vulnerability in Pheap 2.0
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used to (1) obtain sensitive information, including the administrator password, via settings.php or (2) upload and execute arbitrary PHP code via an update_doc action in edit.php.
network
low complexity
pheap CWE-264
critical
10.0