Lucene search

K
nvd[email protected]NVD:CVE-2008-5708
HistoryDec 24, 2008 - 6:29 p.m.

CVE-2008-5708

2008-12-2418:29:15
CWE-287
web.nvd.nist.gov
3

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.021

Percentile

89.4%

redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername and newpassword parameters and setting the newisadmin parameter to 1.

Affected configurations

Nvd
Node
slimcmsslimcmsMatch1.0.0
VendorProductVersionCPE
slimcmsslimcms1.0.0cpe:2.3:a:slimcms:slimcms:1.0.0:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.021

Percentile

89.4%

Related for NVD:CVE-2008-5708