CVE-2008-4714
Atomic Photo Album - Authentication Bypass
Title source: ruleDescription
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.
Exploits (1)
Scores
EPSS
0.0226
EPSS Percentile
84.4%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
atomic_photo_album/atomic_photo_album
Timeline
Published
Oct 23, 2008
Tracked Since
Feb 18, 2026