Back

CVE-2006-0440

Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie.

Published: Jan 26, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
text_rider text_rider 2.4

GitHub Security Advisory GHSA-876r-xj39-ff44

Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 1.40%

Top 30% most likely to be exploited

Threat Score 20.4 / 100

Data Sources

NVD EPSS GitHub