CVE-2008-6664

Publication date

2009-04-08 10:00:00

Family

mitre

State

PUBLISHED

Description

action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.