The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://secunia.com/advisories/31249 | third party advisory vendor advisory |
http://www.gulftech.org/?node=research&article_id=00117-07282008 | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44048 | vdb entry |
http://www.jamroom.net/phpBB2/viewtopic.php?t=24454 | patch |
http://www.securityfocus.com/archive/1/494820/100/0/threaded | mailing list |
http://www.jamroom.net/index.php?m=td_tracker&o=view&id=1178 | |
http://securityreason.com/securityalert/4069 | third party advisory |
http://www.securityfocus.com/bid/30406 | vdb entry exploit |