Authentication Bypass in Active PHP Bookmarks by ActivePHP
CVE-2003-1255

Currently unrated

Key Information:

Vendor
CVE Published:
31 December 2003

What is CVE-2003-1255?

A security issue exists in Active PHP Bookmarks version 1.1.01, where attackers can exploit a vulnerability in the add_bookmark.php script. This flaw allows unauthorized users to add bookmarks on behalf of legitimate users by manipulating the auth_user_id parameter. Consequently, this could lead to unauthorized content being associated with other users' accounts, potentially breaching user privacy and trust.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.