VYPR
Unrated severityNVD Advisory· Published Feb 22, 2006· Updated Apr 16, 2026

CVE-2006-0844

CVE-2006-0844

Description

Leif M. Wright's Blog 3.5 does not make a password comparison when authenticating an administrator via a cookie, which allows remote attackers to bypass login authentication, probably by setting the blogAdmin cookie.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.