Lucene search

K
cve[email protected]CVE-2008-7188
HistorySep 09, 2009 - 5:30 p.m.

CVE-2008-7188

2009-09-0917:30:01
CWE-264
web.nvd.nist.gov
19
clipshare
remote attackers
user profiles
password recovery
security vulnerability
cve-2008-7188

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.022 Low

EPSS

Percentile

89.4%

ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a modified uid variable to siteadmin/useredit.php. NOTE: this can be used to recover the password of the user by using the modified e-mail address in the email parameter to recoverpass.php.

Affected configurations

NVD
Node
clip-shareclipshareMatch2.6

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.022 Low

EPSS

Percentile

89.4%

Related for CVE-2008-7188