5
CVSSv2

CVE-2008-0329

Published: 17/01/2008 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote malicious users to accept comments, delete comments, and delete articles via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

julien plesniak lulieblog 1.0.1

julien plesniak lulieblog 1.0.2

Exploits

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- LulieBlog 101 (delete id) Remote Admin Bypass Vulnerability -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- bug found by ka0x contact: <ka0x01[at]gmailcom> DOM TEAM 2008 we are: ka0x, an0de, xarnuz #from spain download: wwwcomscriptscom/scripts/phplul ...