6.8
CVE-2008-4484
- EPSS 9.56%
- Veröffentlicht 08.10.2008 02:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Crux Software ≫ Gallery Updatephp5 Version <= 1.32
Crux Software ≫ Gallery Version1.0
Crux Software ≫ Gallery Version1.1
Crux Software ≫ Gallery Version1.2
Crux Software ≫ Gallery Version1.30
Crux Software ≫ Gallery Version1.31
Crux Software ≫ Gallery Version1.32
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.56% | 0.926 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|