Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-5219

Опубликовано: 25 нояб. 2008
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:videoscript:videoscript:*:*:*:*:*:*:*:*
Версия до 4.0.1.50 (включая)

EPSS

Процентиль: 87%
0.03579
Низкий

7.5 High

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
больше 3 лет назад

The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require knowledge of the original password, which allows remote attackers to change the admin account password via modified npass and npass1 parameters.

EPSS

Процентиль: 87%
0.03579
Низкий

7.5 High

CVSS2

Дефекты

CWE-287