6.8
CVE-2008-7024
- EPSS 2.53%
- Veröffentlicht 21.08.2009 14:30:00
- Zuletzt bearbeitet 16.06.2026 23:03:26
- Erkennungen
admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Arzdev ≫ Gemini Lite Version 3.5
Arzdev ≫ Gemini Lite Version 3.6
Arzdev ≫ Gemini Portal Version 4.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.53% | 0.829 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/32057
http://osvdb.org/48639
http://www.securityfocus.com/archive/1/496761/100/0/threaded
http://www.securityfocus.com/bid/31429
https://exchange.xforce.ibmcloud.com/vulnerabilities/45439
https://www.exploit-db.com/exploits/6584