Логотип exploitDog
bind:CVE-2009-1771
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2009-1771

Количество 2

Количество 2

nvd логотип

CVE-2009-1771

больше 16 лет назад

index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters.

CVSS2: 7.5
EPSS: Низкий
github логотип

GHSA-fwp9-4j6x-wfhj

почти 4 года назад

index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2009-1771

index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters.

CVSS2: 7.5
3%
Низкий
больше 16 лет назад
github логотип
GHSA-fwp9-4j6x-wfhj

index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters.

3%
Низкий
почти 4 года назад

Уязвимостей на страницу