7.5
CVSSv2

CVE-2005-4174

Published: 11/12/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

eFiction 1.0, 1.1, and 2.0, in unspecified environments, might allow remote malicious users to conduct unauthorized operations by directly accessing (1) install.php or (2) upgrade.php. NOTE: it is unclear whether this is a vulnerability in eFiction itself or the result of incorrect system administration practices, e.g. by not removing utility scripts once they have been used.

Vulnerable Product Search on Vulmon Subscribe to Product