CVE-2009-0412

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
03/02/2009
Last modified:
09/04/2025

Description

The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:interspire:shopping_cart:4.0.1:*:*:*:*:*:*:*