Required CVE Record Information
Description
cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.
References 4 Total
- securityfocus.com: 20070411 Cosign SSO Authentication Bypass mailing-list
- secunia.com: 24845 third-party-advisory
- vupen.com: ADV-2007-1359 vdb-entry
- http://www.umich.edu/~umweb/software/cosign/cosign-vuln-2007-002.txt
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 4 Total
- securityfocus.com: 20070411 Cosign SSO Authentication Bypass mailing-listx_transferred
- secunia.com: 24845 third-party-advisoryx_transferred
- vupen.com: ADV-2007-1359 vdb-entryx_transferred
- http://www.umich.edu/~umweb/software/cosign/cosign-vuln-2007-002.txt x_transferred