CVE-2009-1618

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
12/05/2009
Last modified:
09/04/2025

Description

Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&usr=&alias=admin&userid=1 value for the TWLHadmin cookie.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:teraway:livehelp:2.0:*:*:*:*:*:*:*