CVE-2009-4987

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
25/08/2010
Last modified:
11/04/2025

Description

admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting the cookgid cookie value to 1, a different vector than CVE-2008-3211.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:scripteen:free_image_hosting_script:2.3:*:*:*:*:*:*:*