VulnerabilityModified
CVE-2008-4484
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.
MEDIUM 6.8EPSS 2.57%
Does this matter?
Lower severity and a low EPSS score (2.57%). Track it; it rarely justifies an emergency change on its own.
Description
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.57% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- crux software/gallery
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/32058Vendor Advisory
- http://securityreason.com/securityalert/4365
- http://www.attrition.org/pipermail/vim/2008-October/002083.html
- http://www.securityfocus.com/archive/1/496763/100/0/threaded
- http://www.securityfocus.com/bid/31430
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45443
- https://www.exploit-db.com/exploits/6586
- http://secunia.com/advisories/32058Vendor Advisory
- http://securityreason.com/securityalert/4365
- http://www.attrition.org/pipermail/vim/2008-October/002083.html
- http://www.securityfocus.com/archive/1/496763/100/0/threaded
- http://www.securityfocus.com/bid/31430
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45443
- https://www.exploit-db.com/exploits/6586
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.