7.5
CVSSv2

CVE-2009-3949

Published: 16/11/2009 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

cp/profile.php in VivaPrograms Infinity 2.0.5 and previous versions does not require administrative authentication for the donewauthor action, which allows remote malicious users to create administrative accounts via the name, password, and conf_password parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

vivaprograms infinity script

vivaprograms infinity script 2.0.0

Exploits

<?php print_r(' || || | || o_,_7 _|| _o_7 _|| q_|_|| o_///_, ( : / (_) / ( ___________________ _/QQQQQQQQQQQQQQQQQQQ ...