7.5
CVE-2008-3211
- EPSS 3.26%
- Veröffentlicht 18.07.2008 15:13:00
- Zuletzt bearbeitet 16.06.2026 22:55:22
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Scripteen ≫ Free Image Hosting Script Version1.2
Scripteen ≫ Free Image Hosting Script Version1.2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.26% | 0.867 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://secunia.com/advisories/31083
http://securityreason.com/securityalert/4014
http://www.securityfocus.com/bid/30217
http://www.vupen.com/english/advisories/2008/2106/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/43771
https://www.exploit-db.com/exploits/6070