Lucene search

K
nvd[email protected]NVD:CVE-2015-6655
HistoryAug 31, 2015 - 7:59 p.m.

CVE-2015-6655

2015-08-3119:59:00
CWE-352
web.nvd.nist.gov
3

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

64.5%

Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via a request to admin/admin_users.php.

Affected configurations

Nvd
Node
pliggpligg_cmsMatch2.0.2
VendorProductVersionCPE
pliggpligg_cms2.0.2cpe:2.3:a:pligg:pligg_cms:2.0.2:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.002

Percentile

64.5%