Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4245

Опубликовано: 25 сент. 2008
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or perform unspecified other administrative actions via vectors involving an admin lista action to the default URI, possibly related to useradmin.php.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rianxosencabos_cms:rianxosencabos_cms:0.9:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.03779
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or perform unspecified other administrative actions via vectors involving an admin lista action to the default URI, possibly related to useradmin.php.

EPSS

Процентиль: 88%
0.03779
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-264