Lucene search

K
cveMitreCVE-2009-1637
HistoryMay 15, 2009 - 3:30 p.m.

CVE-2009-1637

2009-05-1515:30:00
CWE-264
mitre
web.nvd.nist.gov
23
cve-2009-1637
simple customer 1.3
profile.php
unauthorized access
admin email
password change

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

7.1

Confidence

Low

EPSS

0.027

Percentile

90.6%

profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and password parameters.

Affected configurations

Nvd
Node
simplecustomersimple_customerMatch1.3
VendorProductVersionCPE
simplecustomersimple_customer1.3cpe:2.3:a:simplecustomer:simple_customer:1.3:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

7.1

Confidence

Low

EPSS

0.027

Percentile

90.6%

Related for CVE-2009-1637