Loading vulnerability details…
CVSS v3.1
N/A
EPSS
2.77%
Published
May 20, 2009
Modified
Apr 22, 2026
Public PoC / Exploit (2)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including administrative privileges, by setting the authuser cookie parameter to a valid username.
Weaknesses (CWE)
Affected Products (1)
References (10)