10
CVSSv2

CVE-2006-1085

Published: 09/03/2006 Updated: 18/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

admin.php in PHP-Stats 0.1.9.1 and previous versions allows remote malicious users to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[admin_pass] parameter and setting the pass_cookie to the MD5 hash of the specified password.

Vulnerable Product Search on Vulmon Subscribe to Product

php-stats php-stats