ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid pseudo cookie.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Asp-nuke |
Asp-nuke |
rc1 (including) |
rc1 (including) |
Asp-nuke |
Asp-nuke |
rc2 (including) |
rc2 (including) |
References