8.8

CVE-2004-1703

Exploit
Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FusionphpFusion News Version3.6.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.96% 0.778
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

http://marc.info/?l=bugtraq&m=109122824523226&w=2
Mailing List
http://securitytracker.com/id?1010829
Third Party Advisory
Vendor Advisory
Exploit
Broken Link
VDB Entry
http://www.securityfocus.com/bid/10836
Third Party Advisory
Vendor Advisory
Exploit
Broken Link
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16853
Third Party Advisory
VDB Entry