CVE-2008-4714
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
23/10/2008
Last modified:
09/04/2025
Description
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:atomic_photo_album:atomic_photo_album:1.1.0:pre4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page