CVE-2009-0460
Published Feb 10, 2009Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.
Vendor/product archive
2 CVEs tagged to wholehogsoftware / ware_support — 0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cookie.
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (…