7.5
CVSSv2

CVE-2008-1971

Published: 27/04/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

phShoutBox Final 1.5 and previous versions only checks passwords when specified in $_POST, which allows remote malicious users to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and previous versions, the ssbadmin cookie to shoutadmin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

phphq phshoutbox final

Exploits

--==+================================================================================+==-- --==+ PhShoutBox <= 15 (final) Insecure Cookie Handling (Arbitrary Authentication) +==-- --==+================================================================================+==-- Discovered By: t0pP8uZz Discovered On: 18 April 2008 Script Download: h ...