An issue was discovered in damiCMS V6.0.1. It relies on the PHP time() function for cookies, which makes it possible to determine the cookie for an existing admin session via 10800 guesses.
References
Link | Resource |
---|---|
https://github.com/howchen/howchen/issues/2 | Exploit Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2018-08-30T22:00:00
Updated: 2018-08-30T22:57:01
Reserved: 2018-08-30T00:00:00
Link: CVE-2018-16239
JSON object: View
NVD Information
Status : Analyzed
Published: 2018-08-30T22:29:00.973
Modified: 2019-10-03T00:03:26.223
Link: CVE-2018-16239
JSON object: View
Redhat Information
No data.
CWE