Lucene search

K
cve[email protected]CVE-2009-4563
HistoryJan 04, 2010 - 9:30 p.m.

CVE-2009-4563

2010-01-0421:30:00
CWE-79
web.nvd.nist.gov
21
csrf
vulnerability
zenphoto
remote attackers
hijack
authentication
administrators
administrative password
saveoptions action

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.5 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

66.1%

Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via the 0-adminpass and 0-adminpass_2 parameters in a saveoptions action.

Affected configurations

NVD
Node
zenphotozenphotoMatch1.2.5
CPENameOperatorVersion
zenphoto:zenphotozenphotoeq1.2.5

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.5 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

66.1%

Related for CVE-2009-4563