Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3033

Опубликовано: 07 июл. 2008
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rss_aggregator:rss_aggregator:1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01862
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
почти 4 года назад

RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php and (2) a TpsRafraich request to modifier_tps_rafraich.php.

EPSS

Процентиль: 83%
0.01862
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-287