← Back

CVE-2007-3420

nvd nist
Published: Jun 26, 2007Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) username, (2) password, (3) usertheme, and (4) userlang cookies for unauthorized users, which has unknown impact and remote attack vectors.

Affected (1)

Products: Web App.org: Webapp
1 product
Webapp
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.9.9.6

References (6)

Timeline

No history available yet.