6.5
CVSSv2

CVE-2008-4245

Published: 25/09/2008 Updated: 29/09/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or perform unspecified other administrative actions via vectors involving an admin lista action to the default URI, possibly related to useradmin.php.

Vulnerable Product Search on Vulmon Subscribe to Product

rianxosencabos cms rianxosencabos cms 0.9

Exploits

============================================================ Rianxosencabos CMS 09 Arbitrary Add-Admin Vulnerability ============================================================ ,--^----------,--------,-----,-------^--, | ||||||||| `--------' | O CWH Underground Hacking Team `+---------------------------^----------| ...