6.8
CVSSv2

CVE-2014-6046

Published: 28/08/2018 Updated: 01/11/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ prior to 2.8.13 allow remote malicious users to hijack the authentication of unspecified users for requests that (1) delete active users by leveraging improper validation of CSRF tokens or that (2) delete open questions, (3) activate users, (4) publish FAQs, (5) add or delete Glossary, (6) add or delete FAQ news, or (7) add or delete comments or add votes by leveraging lack of a CSRF token.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyfaq phpmyfaq

Exploits

#Title: phpMyFAQ 28X - Multiple Vulnerabilities #Vendor: phpmyfaqde #Date: 040919 #Version: >= 2812 (Latest ATM) #Tested on: Apache 22 / PHP 54 / Linux #Contact: smash [at] devilteampl 1) Persistent XSS Administrator is able to view information about specific user session in 'Statistic' tab Over there, you may find informations ...