CVE Vulnerabilities

CVE-2009-2025

Published: Jun 09, 2009 | Modified: Sep 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values.

Affected Software

Name Vendor Start Version End Version
Dm_filemanager Dutchmonkey 3.9.2 (including) 3.9.2 (including)

References