CVE Vulnerabilities

CVE-2009-1283

Published: Apr 09, 2009 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka User Masquerading. NOTE: this can be leveraged with a separate SQL injection vulnerability to steal hashes.

Affected Software

Name Vendor Start Version End Version
Glfusion Glfusion 1.0.0 1.0.0
Glfusion Glfusion 1.0.2 1.0.2
Glfusion Glfusion 1.0.1 1.0.1
Glfusion Glfusion 1.0.0 1.0.0
Glfusion Glfusion 1.1.1 1.1.1
Glfusion Glfusion * 1.1.2
Glfusion Glfusion 1.0.0 1.0.0
Glfusion Glfusion 1.1.0 1.1.0
Glfusion Glfusion 1.1.0 1.1.0

References