CVE

Id
25590  
CVE No.
CVE-2007-2233  
Status
Candidate  
Description
cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR ( ) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.  
Phase
Assigned (20070425)  
Votes
None (candidate not yet proposed)  
Comments