10

CVE-2007-4338

Exploit
index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's name in the value of an fcms_login_id cookie.  NOTE: this can be leveraged for code execution via a POST with PHP code in the content parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.93% 0.946
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/39534
http://secunia.com/advisories/26421
Vendor Advisory
http://securityreason.com/securityalert/3009
http://sourceforge.net/tracker/index.php?func=detail&aid=1778696&group_id=189733&atid=930513
http://www.attrition.org/pipermail/vim/2007-August/001762.html
http://www.attrition.org/pipermail/vim/2007-August/001768.html
http://www.securityfocus.com/archive/1/476142/100/0/threaded
http://www.securityfocus.com/archive/1/476293/100/0/threaded
http://www.securityfocus.com/bid/25276
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/35966