VulnerabilityModified
CVE-2009-1767
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.
MEDIUM 5.0EPSS 2.08%
Does this matter?
Lower severity and a low EPSS score (2.08%). Track it; it rarely justifies an emergency change on its own.
Description
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- 2daybiz/template monster clone
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/35090Vendor Advisory
- http://www.securityfocus.com/bid/34977Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50561
- https://www.exploit-db.com/exploits/8691
- http://secunia.com/advisories/35090Vendor Advisory
- http://www.securityfocus.com/bid/34977Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50561
- https://www.exploit-db.com/exploits/8691
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.