CVE-2008-4784
Aflog - Authentication Bypass
Title source: ruleDescription
aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) edit_delete.php, (2) edit_cat.php, (3) edit_lock.php, and (4) edit_form.php.
Exploits (1)
References (4)
Scores
EPSS
0.0226
EPSS Percentile
84.4%
Classification
CWE
CWE-287
Status
draft
Affected Products (1)
aflog/aflog
Timeline
Published
Oct 29, 2008
Tracked Since
Feb 18, 2026