7.5
CVSSv2

CVE-2008-2682

Published: 12/06/2008 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

_RealmAdmin/login.asp in Realm CMS 2.3 and previous versions allows remote malicious users to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserName, and (3) cUserID.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

realm project realm cms 2.3

Exploits

########################## wwwBugReportir ####################################### # # AmnPardaz Security Research Team # # Title: Realm CMS Multiple Vulnerabilities Lead to Admin Access # Vendor: wwwrealmprojectcom # Vulnerable Version: 23 and prior versions # Exploit: Available # Impact: High # Fix: N/A # Original Advisory: bug ...