CVE-2008-4714

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
23/10/2008
Last modified:
09/04/2025

Description

Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:atomic_photo_album:atomic_photo_album:1.1.0:pre4:*:*:*:*:*:*