7.5
CVSSv2

CVE-2009-4222

Published: 07/12/2009 Updated: 08/12/2009
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

phpBazar 2.1.1fix and previous versions does not require administrative authentication for admin/admin.php, which allows remote malicious users to obtain access to the admin control panel via a direct request.

Vulnerable Product Search on Vulmon Subscribe to Product

smartisoft phpbazar 2.0.2

smartisoft phpbazar 2.1.0

smartisoft phpbazar 2.1.1fix

smartisoft phpbazar

Exploits

phpBazar-211fix Remote Administration-Panel Vulnerability <<!>> Found by? :? kurdish hackers team <<!>> C0ntact : pshela [at] YaHoo com ?????????????????? <<!>> Groups : Kurd-Team <<!>> site?? : wwwkurdteamorg ======================================================= +++++++++++++++++++ Scr ...