7.5
CVSSv2

CVE-2008-1507

Published: 25/03/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PEEL, possibly 3.x and previous versions, has (1) a default info@peel.fr account with password admin, and (2) a default contact@peel.fr account with password cinema, which allows remote malicious users to gain administrative access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

peel peel

peel peel 1.0b

peel peel 2.6

peel peel 2.7

Exploits

#!/usr/bin/php <?php /*---------------------------------------------------------------*\ * * Exploit: PEEL CMS Admin Hash Extraction and Remote Upload * Credits: Charles "real" F <charlesfol[at]hotmailfr> * URL: realnfreefr/ * Date: 03-18-08 * * Targets: PEEL PREMIUM PEEL POWERSELL * PEEL INTEGRALE PEEL PROFESSIO ...