CVE-2009-3168
7.2
CVSS Score
High
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Link copied!
Description
Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request.
CVSS Vector Details
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Software Configurations
- a mevin basic_php_events_lister 2.0 * * * * * * *
Weaknesses (CWE)
- CWE-862
- CWE-862
References & External Links
- http://secunia.com/advisories/36525
- http://www.exploit-db.com/exploits/9558
- http://www.osvdb.org/57595
- http://www.securityfocus.com/bid/36198
- http://www.vupen.com/english/advisories/2009/2497
- http://secunia.com/advisories/36525
- http://www.exploit-db.com/exploits/9558
- http://www.osvdb.org/57595
- http://www.securityfocus.com/bid/36198
- http://www.vupen.com/english/advisories/2009/2497
External Resources
CVE History Timeline
Sep 14, 2009 11:26
Initial Analysis
Sep 19, 2017 01:29
CVE Modified
Jan 25, 2024 21:51
Modified Analysis
May 14, 2024 02:09
CVE Modified
Nov 21, 2024 01:06
CVE Modified
Jan 21, 2025 17:15
CVE Modified