6.8
CVE-2008-4484
- EPSS 2.58%
- Veröffentlicht 08.10.2008 02:00:01
- Zuletzt bearbeitet 16.06.2026 22:57:54
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Crux Software ≫ Gallery Updatephp5 Version <= 1.32
Crux Software ≫ Gallery Version1.0
Crux Software ≫ Gallery Version1.1
Crux Software ≫ Gallery Version1.2
Crux Software ≫ Gallery Version1.30
Crux Software ≫ Gallery Version1.31
Crux Software ≫ Gallery Version1.32
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.58% | 0.832 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/32058
http://securityreason.com/securityalert/4365
http://www.attrition.org/pipermail/vim/2008-October/002083.html
http://www.securityfocus.com/archive/1/496763/100/0/threaded
http://www.securityfocus.com/bid/31430
https://exchange.xforce.ibmcloud.com/vulnerabilities/45443
https://www.exploit-db.com/exploits/6586