7.5

CVE-2005-1787

Exploit
setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhpstatPhpstat Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 12.35% 0.957
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://marc.info/?l=bugtraq&m=111721290726958&w=2
Mailing List
http://secunia.com/advisories/15516
Third Party Advisory
Permissions Required
http://securitytracker.com/id?1014064
Third Party Advisory
VDB Entry
http://www.soulblack.com.ar/repo/papers/advisory/PhpStat_advisory.txt
Broken Link
http://www.soulblack.com.ar/repo/tools/sbphpstatpoc.txt
Vendor Advisory
Exploit