CVE-2008-5873

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
08/01/2009
Last modified:
09/04/2025

Description

Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a value beginning with 1:1: followed by a username.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yerba:yerba:*:*:*:*:*:*:*:* 6.3 (including)
cpe:2.3:a:yerba:yerba:6.28:*:*:*:*:*:*:*