2.6
CVSSv2

CVE-2008-0266

Published: 15/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 265
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote malicious users to change the administrative password and possibly perform other administrative tasks. NOTE: either the old password must be known, or the attacker must leverage a separate SQL injection vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

eticket eticket 1.5.5.2

Exploits

source: wwwsecurityfocuscom/bid/27173/info eTicket is prone to multiple input-validation vulnerabilities because the application fails to properly sanitize user-supplied input These vulnerabilities include multiple SQL-injection issues, a cross-site scripting issue, and an authentication-bypass issue A successful exploit could allow an ...