Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-5076

Опубликовано: 08 июн. 2011
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privileges via a request with (1) login.php or (2) password_forgotten.php appended as the PATH_INFO, which bypasses a check that uses PHP_SELF, which is not properly handled by (a) includes/application_top.php and (b) admin/includes/application_top.php, as exploited in the wild in 2009.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:creloaded:cre_loaded:*:*:*:*:*:*:*:*
Версия до 6.2 (включая)
cpe:2.3:a:creloaded:cre_loaded:6.3:*:*:*:*:*:*:*
cpe:2.3:a:creloaded:cre_loaded:6.15:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00229
Низкий

7.5 High

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
почти 4 года назад

CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privileges via a request with (1) login.php or (2) password_forgotten.php appended as the PATH_INFO, which bypasses a check that uses PHP_SELF, which is not properly handled by (a) includes/application_top.php and (b) admin/includes/application_top.php, as exploited in the wild in 2009.

EPSS

Процентиль: 45%
0.00229
Низкий

7.5 High

CVSS2

Дефекты

CWE-287