7.5
CVSSv2

CVE-2009-1780

Published: 22/05/2009 Updated: 20/05/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

admin.php in Frax.dk Php Recommend 1.3 and previous versions does not require authentication when the user password is changed, which allows remote malicious users to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

frax php recommend

Exploits

Php Recommend <=13 Authentication Bypass/Remote File Include/Code Injection Exploits Author: scriptjunkie scriptjunkie1 {nospam} googlemail {nospam} com Condition: RFI: allow_url_fopen = On code injection: magic_quotes_gpc = Off Exploits: Authentication Bypass: change admin username and password: vulnerablecom/adminphp?submit=submit&amp ...