Heap
13-05-09, 03:05
** DISPUTED ** Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the COOKIE_LAST_ADMIN_USER and COOKIE_LAST_ADMIN_LANG cookies. NOTE: a third party reports that the vendor disputes the existence of this issue.
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6804)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-6804)