CVE-2013-7137

The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:burden_project:burden:1.4:*:*:*:*:*:*:*
cpe:2.3:a:burden_project:burden:1.5:*:*:*:*:*:*:*
cpe:2.3:a:burden_project:burden:1.2:*:*:*:*:*:*:*
cpe:2.3:a:burden_project:burden:1.3:*:*:*:*:*:*:*
cpe:2.3:a:burden_project:burden:*:*:*:*:*:*:*:*
cpe:2.3:a:burden_project:burden:1.6:*:*:*:*:*:*:*
cpe:2.3:a:burden_project:burden:1.7:*:*:*:*:*:*:*

Information

Published : 2014-01-26 01:55

Updated : 2022-02-18 22:04


NVD link : CVE-2013-7137

Mitre link : CVE-2013-7137


JSON object : View

Products Affected

burden_project

  • burden
CWE
CWE-287

Improper Authentication