7.5

CVE-2008-1971

Exploit
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhphqPhshoutbox Final Version <= 1.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.21% 0.803
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

http://secunia.com/advisories/29892
Vendor Advisory
http://www.securityfocus.com/bid/28856
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/41901
https://www.exploit-db.com/exploits/5467