CVE-2013-7137
critical · 9.8The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.
9.8
CVSS
16.1%
EPSS (exploit prob.)
97th
EPSS percentile
2014-01-26
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| burden_project | burden | < 1.8.1 |
Check a specific version with /api/v1/cve/match.
References
- http://www.exploit-db.com/exploits/30916
- http://www.securityfocus.com/archive/1/530703/100/0/threaded
- https://github.com/joshf/Burden/commit/edaa1bb8f73d6f3c8b2e78b67f1b40e02fccd0c1
- https://github.com/joshf/Burden/issues/2
- https://github.com/joshf/Burden/releases/tag/1.8.1
- https://www.htbridge.com/advisory/HTB23192
- http://www.exploit-db.com/exploits/30916
- http://www.securityfocus.com/archive/1/530703/100/0/threaded
- https://github.com/joshf/Burden/commit/edaa1bb8f73d6f3c8b2e78b67f1b40e02fccd0c1
- https://github.com/joshf/Burden/issues/2
- https://github.com/joshf/Burden/releases/tag/1.8.1
- https://www.htbridge.com/advisory/HTB23192
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-7137