6
CVSSv2

CVE-2007-5918

Published: 10/11/2007 Updated: 15/10/2018
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 605
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in edit.php in the MS TopSites add-on for PHP-Nuke does not verify that the uname parameter matches the current account, which allows remote authenticated users to change arbitrary accounts or change the SiteTitleName field as an arbitrary user via a modified uname value in an edit action to modules.php.

Vulnerable Product Search on Vulmon Subscribe to Product

ms topsites ms topsites

Exploits

source: wwwsecurityfocuscom/bid/26358/info MS-TopSites is prone to an unauthorized-access vulnerability and an HTML-injection vulnerability because the application fails to sufficiently sanitize user-supplied data An attacker can exploit these issues to gain elevated privileges on the affected application, execute arbitrary code within ...