First published: Fri Mar 26 2010(Updated: )
The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tiki Tikiwiki Cms\/groupware | =3.2 | |
Tiki Tikiwiki Cms\/groupware | =3.1 | |
Tiki Tikiwiki Cms\/groupware | =3.0 | |
Tiki Tikiwiki Cms\/groupware | =3.3 | |
Tiki Tikiwiki Cms\/groupware | =3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.