8.8

CVE-2004-1703

Exploit
Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that contains an img bbcode tag that calls index.php with the signup action, which is executed when the administrator's browser loads the page with the img tag.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FusionphpFusion News Version3.6.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.96% 0.778
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

http://marc.info/?l=bugtraq&m=109122824523226&w=2
Mailing List
http://securitytracker.com/id?1010829
Third Party Advisory
Vendor Advisory
Exploit
Broken Link
VDB Entry
http://www.securityfocus.com/bid/10836
Third Party Advisory
Vendor Advisory
Exploit
Broken Link
VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16853
Third Party Advisory
VDB Entry