CVE Vulnerabilities

CVE-2008-5784

Reliance on Cookies without Validation and Integrity Checking

Published: Dec 31, 2008 | Modified: Apr 09, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.

Weakness

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

Affected Software

NameVendorStart VersionEnd Version
V3_chat_profiles_dating_scriptV3chat3.0.2 (including)3.0.2 (including)

Potential Mitigations

References