5
CVE-2009-1767
- EPSS 2.08%
- Veröffentlicht 22.05.2009 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:08:01
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
2daybiz ≫ Template Monster Clone Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.08% | 0.791 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/35090
http://www.securityfocus.com/bid/34977
https://exchange.xforce.ibmcloud.com/vulnerabilities/50561
https://www.exploit-db.com/exploits/8691