Lucene search

K
cve[email protected]CVE-2008-3509
HistoryAug 07, 2008 - 8:41 p.m.

CVE-2008-3509

2008-08-0720:41:00
CWE-94
web.nvd.nist.gov
18
cve-2008-3509
lovecms
admin authentication bypass
remote code execution
security vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.081 Low

EPSS

Percentile

94.4%

LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows remote attackers to change the configuration or execute arbitrary PHP code via addition of blocks, and other vectors.

Affected configurations

NVD
Node
lovecmslovecmsMatch1.6.2
CPENameOperatorVersion
lovecms:lovecmslovecmseq1.6.2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.8 High

AI Score

Confidence

Low

0.081 Low

EPSS

Percentile

94.4%

Related for CVE-2008-3509