CVE-2008-7024
MEDIUM 6.8EPSS 2.5%
admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users."
- CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 2.53% chance of exploitation in the next 30 days, 84th percentile
- Published
- 2009-08-21
- Updated
- 2024-08-07