6.8
CVSSv2

CVE-2008-7156

Published: 02/09/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

EkinBoard 1.1.0 and previous versions, when register_globals is enabled, allows remote malicious users to bypass authorization and gain administrator privileges by setting the _groups[] parameter to 2, as demonstrated via backup.php.

Vulnerable Product Search on Vulmon Subscribe to Product

ekinboard ekinboard

Exploits

----[ EkinBoard Remote File Upload / Auth Bypass ITDefenceru Antichatru ] EkinBoard >= 110 Remote File Upload / Auth Bypass Eugene Minaev underwater@itdefenceru ___________________________________________________________________ ____/ __ __ _______________________ _______ _______________ \ \ \ / \ / ...