Логотип exploitDog
bind:CVE-2008-3509
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2008-3509

Количество 2

Количество 2

nvd логотип

CVE-2008-3509

больше 17 лет назад

LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

CVSS2: 7.5
EPSS: Средний
github логотип

GHSA-q6c8-7rvq-2f39

почти 4 года назад

LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-3509

LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

CVSS2: 7.5
15%
Средний
больше 17 лет назад
github логотип
GHSA-q6c8-7rvq-2f39

LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

15%
Средний
почти 4 года назад

Уязвимостей на страницу