Geeklog Permanent Cookie Account Hijacking Vulnerability

Solution:
The vendor has acknowledged this issue and suggests the following fix:

If you are running Geeklog 1.3 you will need to go to CVS and download the latest copies of system/lib-sessions.php and public_html/users.php.

Additional information is available at the Geeklog homepage(http://geeklog.sourceforge.net/).



 

Privacy Statement
Copyright 2010, SecurityFocus