VendorsCale Dunlapopeninvoice0.90
Vulnerabilities

Cale Dunlap Openinvoice 0.90

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2008-6523
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOTE: this can be leveraged with a separate vulnerability in resetpass.php to modify passwords for arbitrary users.
Published 2009-03-25 · Modified
7.51 PoCEPSS 0.026