VYPR

BellaBook

by BellaBook

CVEs (1)

  • CVE-2007-4416Aug 18, 2007
    risk 0.00cvss epss 0.02

    captcha.php in BellaBook (aka BellaBuffs) allows remote attackers to obtain administrative privileges by sending the admin's username (admin_name) in a pheap_login cookie. NOTE: the vendor disputes this vulnerability because authentication data is derived from the admin_pass…