6.8
CVE-2009-1283
- EPSS 1.26%
- Veröffentlicht 09.04.2009 16:27:57
- Zuletzt bearbeitet 16.06.2026 23:06:56
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this can be leveraged with a separate SQL injection vulnerability to steal hashes.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.26% | 0.657 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/34575
http://www.glfusion.org/article.php/glfusion113
http://marc.info/?l=bugtraq&m=123877379105028&w=2
http://retrogod.altervista.org/9sg_glfuso_sql_cookies.html
http://www.glfusion.org/wiki/doku.php?id=glfusion:whatsnew
https://www.exploit-db.com/exploits/8347