VulnerabilityModified
CVE-2005-2168
delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.
MEDIUM 5.0EPSS 1.09%
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.09% probability · 63th percentile
- CISA KEV
- Not listed
- Affected
- frozenplague.net/plague news system
- Source
- cve@mitre.org
References
- http://dark-assassins.com/forum/viewtopic.php?t=90Vendor Advisory, URL Repurposed
- http://secunia.com/advisories/15902Vendor Advisory
- http://dark-assassins.com/forum/viewtopic.php?t=90Vendor Advisory, URL Repurposed
- http://secunia.com/advisories/15902Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.