Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-2674

Опубликовано: 02 окт. 2011
Источник: nvd
CVSS2: 4.9
EPSS Низкий

Описание

BaserCMS before 1.6.12 does not properly restrict additions to the membership of the operators group, which allows remote authenticated users to gain privileges via unspecified vectors.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:basercms:basercms:*:*:*:*:*:*:*:*
Версия до 1.6.11.4 (включая)
cpe:2.3:a:basercms:basercms:1.5.4:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.5:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.6:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.7:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.8:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.5.9:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.0:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.4:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.5:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.6:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.7:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.7.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.8:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.9:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.9.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.10:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.1:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.2:*:*:*:*:*:*:*
cpe:2.3:a:basercms:basercms:1.6.11.3:*:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00193
Низкий

4.9 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

BaserCMS privilege escallation

EPSS

Процентиль: 41%
0.00193
Низкий

4.9 Medium

CVSS2

Дефекты

CWE-264