CVE-2008-2524

Blogphp - Authentication Bypass

Title source: rule

Description

BlogPHP 2.0 allows remote attackers to bypass authentication, and post (1) messages or (2) comments as an arbitrary user, via a modified blogphp_username field in a cookie.

Scores

EPSS 0.0036
EPSS Percentile 57.4%

Classification

CWE
CWE-287
Status draft

Affected Products (1)

blogphp/blogphp

Timeline

Published Jun 03, 2008
Tracked Since Feb 18, 2026