Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-18941

Опубликовано: 31 янв. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin password in the vgn/ccb/user/mgmt/user/edit/0,1628,0,00.html?uid=admin HTML source code, and then creating a privileged user account. NOTE: this product is discontinued.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vignette:content_management:6:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.00805
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin password in the vgn/ccb/user/mgmt/user/edit/0,1628,0,00.html?uid=admin HTML source code, and then creating a privileged user account. NOTE: this product is discontinued.

EPSS

Процентиль: 74%
0.00805
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200