7.5

CVE-2004-2443

Exploit
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie set to the MD5 hash of a null password, which is compared against the logged session variable by the logged_on function in application.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JawsJaws Version0.2
JawsJaws Version0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.85% 0.945
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/0226.html
Vendor Advisory
http://securitytracker.com/id?1010651
Vendor Advisory
Exploit
http://www.osvdb.org/7724
http://www.securityfocus.com/bid/10670
https://exchange.xforce.ibmcloud.com/vulnerabilities/16622