CVE-2009-0412
The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.55% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- interspire/shopping cart
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/499967/100/0/threaded
- http://www.securityfocus.com/bid/33212
- http://www.securitytracker.com/id?1021557
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47899
- http://www.securityfocus.com/archive/1/499967/100/0/threaded
- http://www.securityfocus.com/bid/33212
- http://www.securitytracker.com/id?1021557
- https://exchange.xforce.ibmcloud.com/vulnerabilities/47899
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.