5.3
CVSSv3

CVE-2014-6047

Published: 28/08/2018 Updated: 23/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

phpMyFAQ prior to 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

phpmyfaq phpmyfaq

Exploits

#Title: phpMyFAQ 28X - Multiple Vulnerabilities #Vendor: phpmyfaqde #Date: 040919 #Version: >= 2812 (Latest ATM) #Tested on: Apache 22 / PHP 54 / Linux #Contact: smash [at] devilteampl 1) Persistent XSS Administrator is able to view information about specific user session in 'Statistic' tab Over there, you may find informations ...