VulnerabilityModified
CVE-2006-5909
generaloptions.php in Paul Tarjan Stanford Conference And Research Forum (SCARF) before 20070227 does not require the admin privilege, which allows remote attackers to reconfigure the application or its user accounts.
MEDIUM 5.0EPSS 1.54%
Does this matter?
Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.
Description
generaloptions.php in Paul Tarjan Stanford Conference And Research Forum (SCARF) before 20070227 does not require the admin privilege, which allows remote attackers to reconfigure the application or its user accounts.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.54% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- paul tarjan/stanford conference and research forum
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/24311Vendor Advisory
- http://sourceforge.net/project/shownotes.php?group_id=177652&release_id=489633
- http://www.securityfocus.com/archive/1/450679/100/0/threaded
- http://www.securityfocus.com/archive/1/460196/100/0/threaded
- http://www.securityfocus.com/bid/20934
- http://www.vupen.com/english/advisories/2007/0760Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30037
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32700
- http://secunia.com/advisories/24311Vendor Advisory
- http://sourceforge.net/project/shownotes.php?group_id=177652&release_id=489633
- http://www.securityfocus.com/archive/1/450679/100/0/threaded
- http://www.securityfocus.com/archive/1/460196/100/0/threaded
- http://www.securityfocus.com/bid/20934
- http://www.vupen.com/english/advisories/2007/0760Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30037
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32700
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.