6.8
CVSSv2

CVE-2008-4484

Published: 08/10/2008 Updated: 11/10/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

main.php in Crux Gallery 1.32 and previous versions allows remote malicious users to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.

Vulnerable Product Search on Vulmon Subscribe to Product

crux software gallery 1.31

crux software gallery 1.30

crux software gallery 1.2

crux software gallery 1.1

crux software gallery 1.0

crux software gallery

crux software gallery 1.32

Exploits

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Crux Gallery <= 132 / Insecure Cookie Handling Vulnerability -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Program: Crux Gallery Version: <= 1,32 File affected: admin/* Download: wwwarzdevcom/downloads/8/Crux Found by Pepelux <pepelux[at]enye-secor ...