CVE-2009-0412

Interspire Shopping Cart <4.0.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication and obtain administrative access by reusing the RememberToken cookie after a failed admin login attempt.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021557
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/33212
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/499967/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/47899

Scores

EPSS 0.0155
EPSS Percentile 71.9%

Details

CWE
CWE-287
Status published
Products (1)
interspire/shopping_cart 4.0.1
Published Feb 03, 2009
Tracked Since Feb 18, 2026